tool-finder

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes unverified data from external package registries, GitHub repositories, and agent skill indexes.\n
  • Ingestion points: The references/tool-finder.md file directs the agent to ingest data from npm, PyPI, crates.io, pkg.go.dev, GitHub, and skills.sh.\n
  • Boundary markers: Instructions in SKILL.md require the agent to provide evidence-backed recommendations with explicit criteria, though there are no explicit delimiters for the external content itself.\n
  • Capability inventory: The skill is limited to search and recommendation tasks and does not include tools for file system modification, network exfiltration, or code execution.\n
  • Sanitization: The instructions explicitly mandate the detection of security red flags, such as known vulnerabilities (CVEs), suspicious installer scripts, and unrestricted bundled shells.\n- [SAFE]: The skill incorporates security-focused evaluation criteria, specifically checking for abandoned tools, known vulnerabilities, and heavy dependency trees before making a recommendation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 05:15 PM
Security Audit — agent-trust-hub — tool-finder