claude-md-enhancer

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill operates by reading and processing untrusted data from a project repository (such as package.json, requirements.txt, and existing CLAUDE.md files) to generate or modify agent instructions, creating a surface for indirect prompt injection.
  • Ingestion points: The InitializationWorkflow class in workflow.py and the CLAUDEMDAnalyzer class in analyzer.py read project configuration files and existing documentation to extract context.
  • Boundary markers: The skill mitigates accidental obedience through an interactive confirmation flow in workflow.py (generate_confirmation_prompt), which requires explicit user approval before files are created or modified.
  • Capability inventory: The skill is granted Read, Write, Edit, and Bash (ls, find, git) permissions, allowing it to automate the creation of path-scoped rule files and project guidelines based on external data.
  • Sanitization: There is no evidence of strict sanitization or filtering of the content extracted from repository files before it is used to populate markdown templates, which could allow malicious repository metadata to influence the generated instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 02:04 AM
Security Audit — agent-trust-hub — claude-md-enhancer