hackathon-finder
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
tinyfishCLI tool alongside standard shell commands such aswhich,cat, andwaitto orchestrate parallel search agents and process their results. - [EXTERNAL_DOWNLOADS]: The skill recommends installing the
@tiny-fish/cliNode.js package and fetches data from established hackathon aggregation platforms including Devpost, MLH, Luma, and Eventbrite. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from third-party websites which creates a potential surface for indirect injection.
- Ingestion points: External hackathon listing pages from Devpost, MLH, Luma, and Eventbrite are read by sub-agents.
- Boundary markers: The instructions provided to sub-agents include constraints such as "STRICT RULES: Do NOT click into any hackathon page" and "Read only what is visible in the listing cards".
- Capability inventory: The skill is capable of executing CLI tools and managing local temporary files in
/tmpto store search results. - Sanitization: The sub-agents are instructed to return structured JSON, which provides basic formatting, but no further sanitization or validation of the ingested text is performed before it is presented to the user.
Audit Metadata