ck

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by processing and displaying content from untrusted local project files.
  • Ingestion points: The commands/init.mjs script extracts project descriptions and goals from README.md and CLAUDE.md. The hooks/session-start.mjs script ingests data from git log and the context.json storage.
  • Boundary markers: The injected content is logically separated from other instructions using markdown headers (e.g., ## ck: SESSION START) and code blocks.
  • Capability inventory: The skill has the capability to read and write files in the ~/.claude/ck/ directory and execute project-specific Node.js scripts via the bash environment.
  • Sanitization: While the scripts perform basic string trimming and length truncation, there is no explicit escaping of instructions or sanitization for prompt-breaking characters.
  • [PROMPT_INJECTION]: The skill uses instructional directives to enforce a specific output format during initialization.
  • The session-start.mjs hook and SKILL.md use directives like 'IMPORTANT: Display the following as your FIRST message, verbatim' to ensure the user sees a context summary. While this is used for legitimate UI purposes, it mirrors patterns found in prompt injection.
  • [COMMAND_EXECUTION]: The skill's interface relies on shell piping to transfer data to its scripts.
  • Instructions in SKILL.md (e.g., echo '<json>' | node ...) require the AI agent to correctly serialize and escape the JSON string to prevent potential shell command injection if the content contains malicious characters.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 11:09 AM
Security Audit — agent-trust-hub — ck