mob-check

Warn

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill instructs the agent in the references/research-to-experiment.md file to generate and execute temporary "ad-hoc verifier" scripts to validate JSON research artifacts. This involves generating executable content at runtime and running it via a subprocess.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from social media and the web, creating a vulnerability surface.\n
  • Ingestion points: Untrusted data enters the agent context through web_search, web_extract, x_search, youtube-content, and gh CLI outputs (referenced in SKILL.md).\n
  • Boundary markers (absent): There are no instructions to use specific delimiters or ignore embedded instructions when synthesizing the gathered data into a brief.\n
  • Capability inventory: The skill executes the bundled scripts/rank.py script and dynamically generated verification scripts as subprocesses.\n
  • Sanitization (absent): The content is processed for ranking but is not sanitized or filtered for prompt injection attacks before synthesis.\n- [COMMAND_EXECUTION]: The skill uses subprocess calls to execute the bundled scripts/rank.py and ad-hoc verification scripts as specified in SKILL.md and references/research-to-experiment.md.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 30, 2026, 03:10 AM
Security Audit — agent-trust-hub — mob-check