creation-guard

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses standard shell utilities such as ls, grep, and head to search for existing automation artifacts within local directories including ~/.claude/skills/, ~/.claude/agents/, ~/.claude/commands/, ~/bin/, and ~/Dev/. These commands are used solely for identifying functional overlap and do not involve administrative privileges or dangerous system modifications.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines an ingestion surface by reading the contents of other local skill and agent files to assess functional overlap. While this presents a theoretical surface for indirect prompt injection if a locally stored file contains malicious instructions, the risk is mitigated by the local scope and the specific goal of artifact analysis.
  • [DATA_EXPOSURE]: The skill accesses local development paths and configuration directories to provide the user with a report on existing capabilities. This information is processed within the agent's context for the purpose of the 'Creation Guard' report and is not transmitted to external domains or third-party services.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 01:52 PM
Security Audit — agent-trust-hub — creation-guard