skills/toy-crane/skills/shape-idea/Gen Agent Trust Hub

shape-idea

Warn

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to "Install what is missing" regarding official vendor agent context, including skills and AGENTS.md codemods. This involves fetching and potentially integrating logic from external, unverified repositories.\n- [COMMAND_EXECUTION]: The instructions require the agent to "make it with a spike or a benchmark" if documentation is unavailable, which implies the generation and execution of code within the environment to verify technical behaviors.\n- [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection (Category 8).\n
  • Ingestion points: The agent is instructed to read the "codebase, the documentation, and authoritative sources" as well as "official docs, issue tracker, or release notes" in SKILL.md.\n
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands within these external documents are provided.\n
  • Capability inventory: The agent can modify local documentation files and execute code via spikes or benchmarks.\n
  • Sanitization: Content from external issue trackers and documentation is processed without explicit validation or sanitization steps.\n- [DATA_EXFILTRATION]: By directing the agent to "official docs, issue tracker, or release notes", the skill creates a path where an agent could be manipulated via malicious content in those external sources to access and potentially transmit project information.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 5, 2026, 06:05 AM
Security Audit — agent-trust-hub — shape-idea