review-proposals
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests untrusted data from a proposals file to update the agent's instructions in
CLAUDE.md. - Ingestion points: The proposals file (SKILL.md, Instruction 2).
- Boundary markers: There are no explicit instructions to use delimiters to isolate proposal content.
- Capability inventory: The skill writes to a specific configuration file in the
~/.claude/plugins/config/directory (SKILL.md, Instruction 4). - Sanitization: The skill mandates human review, requiring an attorney to explicitly confirm changes before any file write occurs.
- [SAFE]: No evidence of obfuscation, exfiltration, hardcoded credentials, or unauthorized command execution was found.
Audit Metadata