medium-research
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted text from external Medium articles via the Freedium mirror to generate summaries and key points.
- Ingestion points: The
scripts/extract.pyscript fetches article HTML, strips tags, and saves the content to local markdown files in/tmp/medium-research-<slug>/. - Boundary markers: The skill instructions do not prescribe the use of delimiters or 'ignore' instructions when the agent reads the article body, making the agent susceptible to instructions embedded within the article text.
- Capability inventory: The agent uses the
Readtool to access the fetched content and theAgentorBashtool to perform NLP tasks (summarization) on that content. - Sanitization: The
strip_htmlfunction inscripts/extract.pyremoves HTML tags, scripts, and styles, but it does not validate or filter the resulting natural language text for prompt injection patterns. - [COMMAND_EXECUTION]: The skill instructions provide Bash command templates that interpolate user-supplied input (
<topic>) directly into shell commands without guidance for sanitization. - Evidence: The instruction
python3 ~/.claude/skills/medium-research/scripts/discover.py --topic "<topic>"uses double quotes, which do not prevent command substitution (e.g.,$(command)) or backticks in many shell environments. - Risk: An attacker-controlled topic string could lead to arbitrary command execution if the platform's shell invocation does not provide its own layer of escaping.
- [DATA_EXFILTRATION]: The skill performs network operations to a non-whitelisted third-party service, potentially exposing user research metadata.
- Evidence: Article URLs are sent to
freedium-mirror.cfdto retrieve content. This reveals the specific articles and topics being researched to a third-party entity described in the skill as a 'clone'. - Risk: This constitutes metadata exposure to an untrusted external domain.
Audit Metadata