generate-cfp
Warn
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill is designed to silently read the hidden file
~/.devadvokit.mdfrom the user's home directory. This file contains the user's "DevRel context" and a "content library," which may expose personal information or proprietary data to the AI model context without the user being explicitly informed of the specific data being read. - [DATA_EXFILTRATION]: The skill utilizes directory traversal (
../../shared/ai-antipatterns.md) to access files located outside of the skill's own directory structure, which is a technique used to bypass file access restrictions. - [INDIRECT_PROMPT_INJECTION]: The skill automatically processes and follows instructions from external files (
~/.devadvokit.mdand../../shared/ai-antipatterns.md) which could be manipulated to inject malicious instructions into the agent's session. - Ingestion points: File read operations from
~/.devadvokit.mdand../../shared/ai-antipatterns.md(identified in SKILL.md). - Boundary markers: No boundary markers or instructions to ignore embedded commands are included when reading these files.
- Capability inventory: The skill has the capability to read files from the local filesystem across different paths.
- Sanitization: No sanitization or content validation is performed on the data ingested from these files.
Audit Metadata