install-behavioral-rules

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill requires the execution of a shell script (inject.sh) to perform environment configuration. While the script performs standard file system operations (creating directories, moving files, and symlinking), it executes with the user's shell permissions.
  • [PERSISTENCE]: The skill modifies configuration files for various AI harnesses (e.g., ~/.claude/CLAUDE.md, ~/.pi/pi.md). These files act as persistent system prompts for the AI agent, ensuring that any instructions placed in the linked AGENTS.md file are applied across all future sessions of those harnesses.
  • [INDIRECT_PROMPT_INJECTION]: The skill sets up an ingestion pipeline for instructions that lacks boundary markers or sanitization. This creates a vulnerability surface where the agent's behavior is governed by an external file (AGENTS.md) which can be updated via the repository. Furthermore, the configuration explicitly directs the agent to read a local file (~/vault/USER.md) described as a 'private overlay', potentially exposing sensitive user data to the agent's context.
  • Ingestion points: AGENTS.md (symlinked to active config files) and ~/vault/USER.md (instructed to be read by the agent).
  • Boundary markers: Absent; the instructions are treated as high-priority behavioral rules without delimiters.
  • Capability inventory: The inject.sh script performs file system modifications including mkdir, mv, and ln -s within the user's home directory.
  • Sanitization: Absent; the skill blindly links to the repository-provided instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 08:53 PM
Security Audit — agent-trust-hub — install-behavioral-rules