dev-pain-finder

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes content scraped from external public platforms (Reddit, Hacker News, dev.to, and GitHub Discussions), which constitutes untrusted input. Maliciously crafted post titles or snippets could attempt to influence the agent's summary or behavior.\n
  • Ingestion points: Data is scraped from four public websites in parallel agents (Step 2).\n
  • Boundary markers: The sub-agents are provided with "STRICT RULES" to extract only specific fields and return data in a JSON array, which helps isolate the content.\n
  • Capability inventory: The skill uses tinyfish agent run to execute remote scraping and handles files in /tmp.\n
  • Sanitization: Content is scraped as raw text and passed to the main agent for clustering and scoring without explicit filtering for instruction-like patterns.\n- [COMMAND_EXECUTION]: The skill constructs shell commands by interpolating user-provided keywords directly into CLI calls for tinyfish agent run and uses redirection to store results in temporary files.\n- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the tinyfish CLI tool and fetching skill data from a community-maintained GitHub repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:41 AM
Security Audit — agent-trust-hub — dev-pain-finder