oss-bounty-finder
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
@tiny-fish/clipackage from the global npm registry. This tool is essential for the skill's core functionality. - [COMMAND_EXECUTION]: The skill utilizes shell commands in bash/zsh and PowerShell environments to perform health checks, manage user authentication status, and execute parallel automation tasks via
tinyfish agent runand background job management (Start-Job,&). - [INDIRECT_PROMPT_INJECTION]: The skill has a broad ingestion surface as it fetches content from numerous external platforms (Algora, IssueHunt, GitHub, NLNet, Mozilla, Google, etc.).
- Ingestion points: SKILL.md defines multiple
tinyfish agent runcommands targeting external URLs to scrape bounty and grant data. - Boundary markers: The instructions provided to the extraction agent (the "goal" parameter) do not include explicit delimiters or "ignore instructions" directives for the fetched web content.
- Capability inventory: The skill environment has capabilities for local shell execution and browser-based web automation.
- Sanitization: The skill expects the agent to parse content into specific JSON structures, providing a level of structural validation, but does not explicitly sanitize the text content for adversarial instructions.
Audit Metadata