clean-code
Warn
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to perform mandatory validation by running Python scripts from a fixed local path. These scripts are executed with the current directory as an argument, allowing them to process the entire codebase.
- Evidence: The 'Verification Scripts' section lists multiple commands like
python ~/.claude/skills/vulnerability-scanner/scripts/security_scan.py .. - [REMOTE_CODE_EXECUTION]: The instructions require the agent to execute code located in hidden subdirectories belonging to other 'skills'. This pattern bypasses the isolation of individual skills and creates a risk where a compromised or malicious skill could place executable files in the
~/.claude/skills/directory to be triggered by this coding standards skill. - Evidence: The instruction '🔴 CRITICAL: Each agent runs ONLY their own skill's scripts after completing work' enforces the automatic execution of these external files.
Audit Metadata