install-to-trash
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides a transparent safety mechanism to protect users from accidental data loss. No malicious patterns, obfuscation, or data exfiltration attempts were found.
- [COMMAND_EXECUTION]: The skill installation involves writing a local Bash script to
~/.claude/hooks/intercept-rm.shand updating the agent'ssettings.jsonto register a PreToolUse hook. These modifications are standard for adding agent functionality and are confined to the agent's managed configuration space. - [PROMPT_INJECTION]: The hook script monitors tool inputs to provide safety feedback, representing a surface for indirect prompt injection.
- Ingestion points: The
intercept-rm.shscript readstool_input.commandfrom the agent's JSON payload provided via stdin. - Boundary markers: None are present in the script's regex-based command analysis.
- Capability inventory: The script analyzes commands and returns a
systemMessagecontaining suggested rewrites to the agent's context. - Sanitization: The script uses
grepfor pattern detection andsedfor command transformation to generate safe alternative suggestions.
Audit Metadata