fpl-copilot

Warn

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPERSISTENCE
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill generates self-contained HTML reports by populating templates with data from the FPL database and user squad files. Since user-supplied fields like 'Notes' are included in these reports without explicit instructions for sanitization, there is a possibility for local Cross-Site Scripting (XSS) when a user opens the generated reports in their local browser environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from the external Fantasy Premier League API and user-managed local markdown files, which serves as an ingestion surface for potentially malicious instructions hidden in player data or squad comments.
  • Ingestion points: Data retrieved from the official FPL API (fantasy.premierleague.com/api) and squad files located in ~/.fplcopilot/squads/.
  • Boundary markers: Absent. No specific delimiters or instructions to ignore embedded content are provided for the data processing steps described in SKILL.md and analysis.md.
  • Capability inventory: The skill can execute shell commands (via sync.sh), query SQLite databases, perform network operations with curl, and generate executable HTML files.
  • Sanitization: Absent. There are no explicit requirements or instructions to escape, validate, or filter data retrieved from the external API or user-authored files.
  • [EXTERNAL_DOWNLOADS]: The sync.sh script downloads football data from the official Fantasy Premier League API. This is a well-known service required for the skill's primary function and the downloads are performed via standard curl commands to the hardcoded official domain.
  • [COMMAND_EXECUTION]: The skill executes a local bash script (sync.sh) and standard utilities like curl, jq, and sqlite3 to manage data synchronization and database queries. These operations are performed within a scoped directory in the user's home folder.
  • [PERSISTENCE]: The skill stores user squad state and analysis notes in markdown files within ~/.fplcopilot/squads/ to maintain data across multiple sessions. This persistence is a core functional requirement of the squad management system described in references/squad.md.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 18, 2026, 08:05 AM
Security Audit — agent-trust-hub — fpl-copilot