tool-finder

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to search for and evaluate external tools, packages, and skills by accessing data from public registries and websites (e.g., npm, PyPI, GitHub, skills.sh).
  • Ingestion points: External data from web search results, package registries (npm, PyPI, etc.), and GitHub repository content (SKILL.md, README).
  • Boundary markers: The skill instructions do not specify using delimiters or specific 'ignore instructions' warnings when processing retrieved web or registry content.
  • Capability inventory: While the skill is purely instructional markdown, the agent using it typically has file-system and network access to conduct research and provide installation commands.
  • Sanitization: The instructions lack explicit requirements for sanitizing or escaping external content before the agent evaluates it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 03:06 PM
Security Audit — agent-trust-hub — tool-finder