capability-assessment

Warn

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill reads the file ~/.claude/history.jsonl, which contains sensitive information such as user chat messages, project names, and pasted code. This data is summarized and transmitted to an external service (Slack) via the Rube MCP.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input stored in local history files which could contain malicious instructions intended to influence the agent's report or actions. • Ingestion points: The display and pastedContents fields within ~/.claude/history.jsonl. • Boundary markers: No delimiters or instructions to ignore embedded content are provided. • Capability inventory: External communication via Slack and web search via HackerNews. • Sanitization: No sanitization or filtering of the history content is described.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 23, 2026, 05:00 PM
Security Audit — agent-trust-hub — capability-assessment