senior-software-engineer

Fail

Audited by Gen Agent Trust Hub on May 3, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses explicit instructions to override the agent's default alignment and helpfulness behaviors, commanding the model to "push back when warranted" and "not be a yes-machine."- [COMMAND_EXECUTION]: The documentation provides shell commands (grep, nano) designed to access and modify internal agent configuration and system prompt files located in the ~/.claude-sneakpeek/ directory, which are outside the typical scope of skill-specific data.- [PROMPT_INJECTION]: The skill claims to have modified the global system prompt file (system-prompt-main-system-prompt.md) to ensure it remains "automatically active" in every session, bypassing the standard user-controlled skill activation mechanism.- [COMMAND_EXECUTION]: The skill documentation describes modifications to the agent's global settings.json to force-enable internal features like alwaysThinkingEnabled, which alters the fundamental reasoning behavior of the agent for all tasks.- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted code and files during refactoring tasks without using boundary markers or sanitization to prevent embedded instructions from influencing its behavior.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
May 3, 2026, 11:06 AM
Security Audit — agent-trust-hub — senior-software-engineer