claude-md-enhancer
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill operates by reading and processing untrusted data from a project repository (such as package.json, requirements.txt, and existing CLAUDE.md files) to generate or modify agent instructions, creating a surface for indirect prompt injection.
- Ingestion points: The
InitializationWorkflowclass inworkflow.pyand theCLAUDEMDAnalyzerclass inanalyzer.pyread project configuration files and existing documentation to extract context. - Boundary markers: The skill mitigates accidental obedience through an interactive confirmation flow in
workflow.py(generate_confirmation_prompt), which requires explicit user approval before files are created or modified. - Capability inventory: The skill is granted
Read,Write,Edit, andBash(ls, find, git) permissions, allowing it to automate the creation of path-scoped rule files and project guidelines based on external data. - Sanitization: There is no evidence of strict sanitization or filtering of the content extracted from repository files before it is used to populate markdown templates, which could allow malicious repository metadata to influence the generated instructions.
Audit Metadata