morph-search
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill exposes an interface for arbitrary file modification using the
--editand--contentparameters. This allows the agent to write any content to any file path accessible to the script, which could be used to overwrite sensitive configurations or inject malicious scripts if the agent is compromised or manipulated. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to search through and ingest codebase content, which is a potential surface for indirect prompt injection.
- Ingestion points: Content from the codebase is retrieved and placed into the agent's context via the
--searchoperation described inSKILL.md. - Boundary markers: There are no specific delimiters or instructions defined to isolate search results or prevent the agent from following instructions found within the code being searched.
- Capability inventory: The skill uses
BashandReadtools, and provides a custom file-writing capability via the--editflag. - Sanitization: The documentation does not describe any sanitization or filtering of the content retrieved from the file system before it is processed by the agent.
Audit Metadata