ask-claude
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a shell pipeline to invoke the
claudeCLI tool. It specifically uses the--model opusand--allowedTools ""flags to ensure the secondary model call is isolated and has no tool access, which is a defensive configuration. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data ('artifacts' and 'attack frames') by piping them directly into the CLI. This constitutes an ingestion point for untrusted content.
- Ingestion points: Text artifacts and attack rubrics piped to stdin of the
claudecommand inSKILL.md. - Boundary markers: The invocation lacks explicit delimiters to isolate the untrusted artifact from the instructions.
- Capability inventory: The skill is limited to text-to-text transport via the
claudecommand and does not have file-write or network capabilities itself. - Sanitization: No explicit sanitization of the input content is performed before the model call.
Audit Metadata