ck
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by processing and displaying content from untrusted local project files.
- Ingestion points: The
commands/init.mjsscript extracts project descriptions and goals fromREADME.mdandCLAUDE.md. Thehooks/session-start.mjsscript ingests data fromgit logand thecontext.jsonstorage. - Boundary markers: The injected content is logically separated from other instructions using markdown headers (e.g.,
## ck: SESSION START) and code blocks. - Capability inventory: The skill has the capability to read and write files in the
~/.claude/ck/directory and execute project-specific Node.js scripts via the bash environment. - Sanitization: While the scripts perform basic string trimming and length truncation, there is no explicit escaping of instructions or sanitization for prompt-breaking characters.
- [PROMPT_INJECTION]: The skill uses instructional directives to enforce a specific output format during initialization.
- The
session-start.mjshook andSKILL.mduse directives like 'IMPORTANT: Display the following as your FIRST message, verbatim' to ensure the user sees a context summary. While this is used for legitimate UI purposes, it mirrors patterns found in prompt injection. - [COMMAND_EXECUTION]: The skill's interface relies on shell piping to transfer data to its scripts.
- Instructions in
SKILL.md(e.g.,echo '<json>' | node ...) require the AI agent to correctly serialize and escape the JSON string to prevent potential shell command injection if the content contains malicious characters.
Audit Metadata