skills/joelhooks/joelclaw/contacts/Gen Agent Trust Hub

contacts

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes the browser, google-search, and x-api tools to fetch data from various external sources including general web pages and social media profiles.
  • [DATA_EXFILTRATION]: Extracted contact details, including names, roles, and social media identifiers, are transmitted to external search providers for enrichment and indexed to a Typesense instance. It also accesses sensitive local directories including ~/Vault/Contacts/ and ~/Code/joelhooks/egghead-roam-research/.
  • [COMMAND_EXECUTION]: Provides embedded Python and Bash scripts intended to search and parse local EDN data files within the user's workspace.
  • [INDIRECT_PROMPT_INJECTION]: Processes untrusted data from web crawls, podcast transcripts, and social media posts, creating a surface for indirect prompt injection where malicious instructions in the source material could influence the LLM's enrichment output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 03:00 AM
Security Audit — agent-trust-hub — contacts