install-behavioral-rules
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill requires the execution of a shell script (
inject.sh) to perform environment configuration. While the script performs standard file system operations (creating directories, moving files, and symlinking), it executes with the user's shell permissions. - [PERSISTENCE]: The skill modifies configuration files for various AI harnesses (e.g.,
~/.claude/CLAUDE.md,~/.pi/pi.md). These files act as persistent system prompts for the AI agent, ensuring that any instructions placed in the linkedAGENTS.mdfile are applied across all future sessions of those harnesses. - [INDIRECT_PROMPT_INJECTION]: The skill sets up an ingestion pipeline for instructions that lacks boundary markers or sanitization. This creates a vulnerability surface where the agent's behavior is governed by an external file (
AGENTS.md) which can be updated via the repository. Furthermore, the configuration explicitly directs the agent to read a local file (~/vault/USER.md) described as a 'private overlay', potentially exposing sensitive user data to the agent's context. - Ingestion points:
AGENTS.md(symlinked to active config files) and~/vault/USER.md(instructed to be read by the agent). - Boundary markers: Absent; the instructions are treated as high-priority behavioral rules without delimiters.
- Capability inventory: The
inject.shscript performs file system modifications includingmkdir,mv, andln -swithin the user's home directory. - Sanitization: Absent; the skill blindly links to the repository-provided instructions.
Audit Metadata