skills/a-canary/arc-skills/ask-claude/Gen Agent Trust Hub

ask-claude

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a shell pipeline to invoke the claude CLI tool. It specifically uses the --model opus and --allowedTools "" flags to ensure the secondary model call is isolated and has no tool access, which is a defensive configuration.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data ('artifacts' and 'attack frames') by piping them directly into the CLI. This constitutes an ingestion point for untrusted content.
  • Ingestion points: Text artifacts and attack rubrics piped to stdin of the claude command in SKILL.md.
  • Boundary markers: The invocation lacks explicit delimiters to isolate the untrusted artifact from the instructions.
  • Capability inventory: The skill is limited to text-to-text transport via the claude command and does not have file-write or network capabilities itself.
  • Sanitization: No explicit sanitization of the input content is performed before the model call.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 07:47 PM
Security Audit — agent-trust-hub — ask-claude