skills/acoz-labs/quickstop/claudit/Gen Agent Trust Hub

claudit

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to discover environment variables, check for the existence of configuration files, and manage the audit workflow. It also executes git and gh CLI commands to handle Pull Request delivery, including branch creation, staging of project-specific configuration changes, and posting review comments via the GitHub API.\n- [EXTERNAL_DOWNLOADS]: The skill fetches best-practice guidelines and configuration references from official Anthropic documentation (docs.anthropic.com). These references are used to build an expert context for the audit subagents. As the source is a trusted organization, this retrieval is considered a safe operation for maintaining up-to-date auditing logic.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests user-controlled content from local and project-level instruction files (e.g., CLAUDE.md, .claude/rules/*.md). This data is processed by subagents, presenting a potential surface for indirect prompt injection if the files contain malicious instructions. The skill employs boundary markers and headers to delimit this content, and its primary purpose is the analysis of these files for user-requested optimization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 02:43 PM
Security Audit — agent-trust-hub — claudit