rules-distill
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes local shell scripts (
scan-skills.shandscan-rules.sh) to catalog files. These scripts use standard POSIX utilities likefind,grep,awk, andjqto process text and metadata. - Evidence: SKILL.md calls
bash ~/.claude/skills/rules-distill/scripts/scan-skills.sh. - [DATA_EXPOSURE]: The tool reads local skill and rule definitions located in
~/.claude/. This access is necessary for its core function of rules management and does not involve external data transmission. - [INDIRECT_PROMPT_INJECTION]: Because the skill processes content from other (potentially third-party) skills, it is subject to indirect prompt injection. A malicious skill could contain instructions intended to influence the rule distillation process. This risk is mitigated by:
- Extraction filters: Principles must appear in at least two skills to be considered.
- Human Review: All changes to rule files require explicit approval from the user as described in Phase 3 of the workflow.
Audit Metadata