speakeasy-context

Warn

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [Prompt Injection] (MEDIUM): The skill creates a vulnerability to indirect prompt injection. It instructs the agent to run speakeasy agent context and use its output as the primary source of truth for subsequent actions.
  • Ingestion points: Output of speakeasy agent context in SKILL.md.
  • Boundary markers: Absent; no instructions are provided to the agent to treat the CLI output as untrusted data.
  • Capability inventory: Ability to execute various speakeasy CLI commands and send data via feedback (SKILL.md).
  • Sanitization: None; the skill lacks validation or escaping for the data received from the CLI.
  • [Data Exfiltration] (LOW): The speakeasy agent feedback command is used to transmit data to an external service. While documented as a feedback mechanism, it represents a routine outbound data flow.
  • [Command Execution] (LOW): The skill is built around executing local CLI commands. It does not attempt to download or install new software, but relies on the existing speakeasy binary.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 01:21 AM