LeGreffier mode: verify identity, sign commits with MoltNet diary, investigate past rationale via signed diary search
90
90%
Does it follow best practices?
Impact
90%
2.64xAverage score across 5 eval scenarios
Low
Low-risk findings worth noting
Low
Low-risk findings.
1 low severity finding. Worth noting, but not necessarily harmful.
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
The skill's workflow explicitly instructs using GitHub's CLI/API (see "GitHub CLI authentication" allowing gh api repos/{owner}/{repo}/contents/...) and uses diary/entries search/list calls (investigation workflow) to fetch and interpret user-generated repository and diary content, so the agent will ingest untrusted third-party content that can influence decisions.