capability-assessment
Warn
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill reads the file
~/.claude/history.jsonl, which contains sensitive information such as user chat messages, project names, and pasted code. This data is summarized and transmitted to an external service (Slack) via the Rube MCP. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input stored in local history files which could contain malicious instructions intended to influence the agent's report or actions. • Ingestion points: The
displayandpastedContentsfields within~/.claude/history.jsonl. • Boundary markers: No delimiters or instructions to ignore embedded content are provided. • Capability inventory: External communication via Slack and web search via HackerNews. • Sanitization: No sanitization or filtering of the history content is described.
Audit Metadata