docs-seeker

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs the agent to perform a global installation of the 'repomix' package (npm install -g repomix) if it is not found on the system. Installing software at runtime from unverified sources introduces significant supply chain risks.
  • [EXTERNAL_DOWNLOADS]: The skill heavily prioritizes 'context7.com' as the primary source for all documentation lookups. This is a third-party, non-trusted documentation aggregator, which presents privacy risks regarding user research topics and potential for content poisoning.
  • [COMMAND_EXECUTION]: The skill uses multiple shell commands, including git clone to download repositories to /tmp and repomix to process them. Additionally, the error handling documentation suggests using pkill -9 to manage hung processes and df/free to monitor system resources.
  • [PRIVILEGE_ESCALATION]: The instruction to install npm packages globally and the suggestion to use pkill for process management involve operations that typically require elevated system privileges.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a large attack surface for indirect prompt injection as it retrieves and processes documentation from third-party aggregators and arbitrary GitHub repositories.
  • Ingestion points: The skill performs WebFetch on llms.txt files from various sources and reads repomix-output.xml generated from cloned GitHub repositories (SKILL.md, references/tool-selection.md).
  • Boundary markers: No specific delimiters or "ignore instructions" warnings are provided to the sub-agents (Explorer/Researcher) when they process this potentially untrusted external content (SKILL.md).
  • Capability inventory: The skill possesses the capability to execute shell commands (git, npm, repomix) and perform network operations (WebFetch) (SKILL.md, references/tool-selection.md).
  • Sanitization: Content retrieved from external sources is not sanitized or validated before being analyzed by the agents (references/best-practices.md).
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 05:08 PM
Security Audit — agent-trust-hub — docs-seeker