rules-distill

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes local shell scripts (scan-skills.sh and scan-rules.sh) to catalog files. These scripts use standard POSIX utilities like find, grep, awk, and jq to process text and metadata.
  • Evidence: SKILL.md calls bash ~/.claude/skills/rules-distill/scripts/scan-skills.sh.
  • [DATA_EXPOSURE]: The tool reads local skill and rule definitions located in ~/.claude/. This access is necessary for its core function of rules management and does not involve external data transmission.
  • [INDIRECT_PROMPT_INJECTION]: Because the skill processes content from other (potentially third-party) skills, it is subject to indirect prompt injection. A malicious skill could contain instructions intended to influence the rule distillation process. This risk is mitigated by:
  • Extraction filters: Principles must appear in at least two skills to be considered.
  • Human Review: All changes to rule files require explicit approval from the user as described in Phase 3 of the workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 11:09 AM
Security Audit — agent-trust-hub — rules-distill