tech-stack-detective
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from multiple external and untrusted sources, including StackShare, LinkedIn, GitHub, Google search results, and arbitrary company websites.
- Ingestion points: Data enters the agent context via
tinyfish agent runcommands targeting external URLs defined inSKILL.md. - Boundary markers: The skill lacks explicit delimiters or instructions for the agent to ignore malicious prompts that might be hidden within the text of the scraped websites (e.g., hidden in job descriptions or engineering blog snippets).
- Capability inventory: The skill possesses the capability to execute shell commands and write data to the local file system (e.g., writing results to
/tmp/). - Sanitization: No sanitization or validation of the externally sourced content is performed before the agent processes it.
- [COMMAND_EXECUTION]: The skill relies on shell command execution to perform its functions, including checking CLI versions, authenticating, and running research agents. User-controlled inputs such as
{COMPANY_DOMAIN}and{COMPANY_SLUG}are interpolated directly into these shell strings, which could lead to command injection if the inputs are not properly sanitized by the platform. - [EXTERNAL_DOWNLOADS]: The instructions guide users to download and install an external package (
@tiny-fish/cli) via npm. This resource is associated with the skill's authoring organization.
Audit Metadata