fpl-copilot
Warn
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPERSISTENCE
Full Analysis
- [DYNAMIC_EXECUTION]: The skill generates self-contained HTML reports by populating templates with data from the FPL database and user squad files. Since user-supplied fields like 'Notes' are included in these reports without explicit instructions for sanitization, there is a possibility for local Cross-Site Scripting (XSS) when a user opens the generated reports in their local browser environment.
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from the external Fantasy Premier League API and user-managed local markdown files, which serves as an ingestion surface for potentially malicious instructions hidden in player data or squad comments.
- Ingestion points: Data retrieved from the official FPL API (fantasy.premierleague.com/api) and squad files located in
~/.fplcopilot/squads/. - Boundary markers: Absent. No specific delimiters or instructions to ignore embedded content are provided for the data processing steps described in SKILL.md and analysis.md.
- Capability inventory: The skill can execute shell commands (via
sync.sh), query SQLite databases, perform network operations withcurl, and generate executable HTML files. - Sanitization: Absent. There are no explicit requirements or instructions to escape, validate, or filter data retrieved from the external API or user-authored files.
- [EXTERNAL_DOWNLOADS]: The
sync.shscript downloads football data from the official Fantasy Premier League API. This is a well-known service required for the skill's primary function and the downloads are performed via standardcurlcommands to the hardcoded official domain. - [COMMAND_EXECUTION]: The skill executes a local bash script (
sync.sh) and standard utilities likecurl,jq, andsqlite3to manage data synchronization and database queries. These operations are performed within a scoped directory in the user's home folder. - [PERSISTENCE]: The skill stores user squad state and analysis notes in markdown files within
~/.fplcopilot/squads/to maintain data across multiple sessions. This persistence is a core functional requirement of the squad management system described in references/squad.md.
Audit Metadata