install-to-trash

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a transparent safety mechanism to protect users from accidental data loss. No malicious patterns, obfuscation, or data exfiltration attempts were found.
  • [COMMAND_EXECUTION]: The skill installation involves writing a local Bash script to ~/.claude/hooks/intercept-rm.sh and updating the agent's settings.json to register a PreToolUse hook. These modifications are standard for adding agent functionality and are confined to the agent's managed configuration space.
  • [PROMPT_INJECTION]: The hook script monitors tool inputs to provide safety feedback, representing a surface for indirect prompt injection.
  • Ingestion points: The intercept-rm.sh script reads tool_input.command from the agent's JSON payload provided via stdin.
  • Boundary markers: None are present in the script's regex-based command analysis.
  • Capability inventory: The script analyzes commands and returns a systemMessage containing suggested rewrites to the agent's context.
  • Sanitization: The script uses grep for pattern detection and sed for command transformation to generate safe alternative suggestions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 01:39 AM
Security Audit — agent-trust-hub — install-to-trash