tool-finder
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes unverified data from external package registries, GitHub repositories, and agent skill indexes.\n
- Ingestion points: The references/tool-finder.md file directs the agent to ingest data from npm, PyPI, crates.io, pkg.go.dev, GitHub, and skills.sh.\n
- Boundary markers: Instructions in SKILL.md require the agent to provide evidence-backed recommendations with explicit criteria, though there are no explicit delimiters for the external content itself.\n
- Capability inventory: The skill is limited to search and recommendation tasks and does not include tools for file system modification, network exfiltration, or code execution.\n
- Sanitization: The instructions explicitly mandate the detection of security red flags, such as known vulnerabilities (CVEs), suspicious installer scripts, and unrestricted bundled shells.\n- [SAFE]: The skill incorporates security-focused evaluation criteria, specifically checking for abandoned tools, known vulnerabilities, and heavy dependency trees before making a recommendation.
Audit Metadata