tool-finder
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to search for and evaluate external tools, packages, and skills by accessing data from public registries and websites (e.g., npm, PyPI, GitHub, skills.sh).
- Ingestion points: External data from web search results, package registries (npm, PyPI, etc.), and GitHub repository content (SKILL.md, README).
- Boundary markers: The skill instructions do not specify using delimiters or specific 'ignore instructions' warnings when processing retrieved web or registry content.
- Capability inventory: While the skill is purely instructional markdown, the agent using it typically has file-system and network access to conduct research and provide installation commands.
- Sanitization: The instructions lack explicit requirements for sanitizing or escaping external content before the agent evaluates it.
Audit Metadata