Activate a DuploCloud project context.
50
55%
Does it follow best practices?
Impact
—
No eval scenarios have been run
Advisory
Suggest reviewing before use
Optimize this skill with Tessl
npx tessl skill review --optimize ./skills/activate_project/SKILL.mdSecurity
1 medium severity finding. This skill can be installed but you should review these findings before use.
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
Third-party content exposure detected (medium risk: 0.65). Outsider free text can enter the LLM context via `duplo-helpdesk::Projects_get` / `Projects_list` responses: the TOON-decoded `spec.content`, `plan.content`, and project `description` (`desc`) are remote, user-unselected text from DuploCloud and are parsed into JSON/plain objects and then used in prompts/tables.
6a46510
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.