inherit-legacy-style

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: Uses local git commands (ls-files, diff, log) to assess project scale and evolution. These operations are standard for repository analysis and are restricted to the local environment.
  • [DATA_EXFILTRATION]: Reads codebase content through Read, Glob, and Grep tools to identify architectural patterns. No network-based exfiltration patterns or unauthorized data access were detected.
  • [PROMPT_INJECTION]: Provides a mechanism to inject persistent behavioral constraints into the agent's reasoning via .ai-style-rules.md and CLAUDE.md. The most invasive 'Hard hook' option (modifying settings.json) is explicitly gated by the AskUserQuestion tool.
  • [PROMPT_INJECTION]: Exhibits a surface for indirect prompt injection as it ingests untrusted codebase data to derive rules. Evidence Chain: Ingestion points include Read and Grep across all source files; Capability inventory includes Bash, Write, and Edit; Sanitization is implemented via the 'Grilling Protocol', which requires human approval of rules and conflicts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 02:47 PM
Security Audit — agent-trust-hub — inherit-legacy-style