claude-code-workshop

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches documentation, changelogs, and summaries from https://code.claude.com/. This targets the official documentation repository for the tool, which is a well-known service and a safe source for this content.
  • [SAFE]: No patterns of prompt injection, obfuscation, persistence, or privilege escalation were detected. The workshop flow is transparent and relies on user-initiated exercises within their own project context.
  • [SAFE]: The skill processes data from external documentation, which constitutes an indirect prompt injection surface. This is assessed as safe as the source is the official documentation for the product being taught. Ingestion points: documentation pages and changelogs fetched from code.claude.com; Boundary markers: not explicitly used in the prompt instructions; Capability inventory: the skill reads local project context (e.g., CLAUDE.md) and suggests terminal commands for the user to try; Sanitization: no explicit sanitization of fetched documentation content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:41 AM
Security Audit — agent-trust-hub — claude-code-workshop