Security risk report for @forgecat/contains-studio_agents_studio-operations v0.1.2
Source Integrity
Low
Profile sourced from GitHub repository (contains-studio/agents) with clear attribution and commit hash (a5a480c324cac64b9c569bca0b2f297d517240cb).
Legitimate open-source distribution via ForgeCat registry; no obfuscation or supply-chain red flags.
Static scanner confirms low risk; source is traceable and verifiable.
Agent Intent
Low
Content describes legitimate operational agent roles (analytics, finance, infrastructure, compliance, support) with standard business functions; no instructions to ignore system prompts, read credentials, or exfiltrate data.
Markdown contains detailed guidance on analytics frameworks, financial modeling, infrastructure optimization, legal compliance, and customer support—all standard business practices without malicious injection or prompt hijacking.
No guidance poisoning detected: recommendations for tool stacks (Google Analytics, Mixpanel, Tableau, etc.) are well-known legitimate services; no typosquatted packages, disabled security defaults, or persistent biased rules that would steer future outputs toward attacker goals.
Details
Evidence
analytics-reporter.md: 'Your goal is to be the studio's compass in the fog of rapid development, providing clear direction based on solid data.'
finance-tracker.md: 'Your goal is to be the studio's financial compass, ensuring every dollar spent moves apps closer to sustainable success.'
infrastructure-maintainer.md: 'Your goal is to be the guardian of studio infrastructure, ensuring applications can handle whatever success throws at them.'
legal-compliance-checker.md: 'Your goal is to be the studio's legal shield, enabling rapid innovation while avoiding costly mistakes.'
support-responder.md: 'Your goal is to be the human face of the studio's rapid development approach, turning potentially frustrated users into understanding allies.'
Permissions
Low
Declared tools (Write, Read, MultiEdit, WebSearch, Grep, Bash for infrastructure-maintainer only) are appropriate to stated agent functions: analytics reporting, financial analysis, infrastructure monitoring, compliance documentation, and support response.
No high-risk categories (shell, file_write, file_delete) with alwaysApply=true and unrestricted globs; Bash tool for infrastructure-maintainer is scoped to performance profiling and monitoring tasks, not arbitrary system access.
Authority matches function: analytics agent uses Read/Write/WebSearch for data analysis; finance agent uses similar for modeling; infrastructure agent includes Bash for legitimate performance and monitoring work; compliance and support agents use documentation tools only.
Details
Evidence
analytics-reporter.md tools: 'Write, Read, MultiEdit, WebSearch, Grep' — appropriate for report generation and data analysis.