skill-extractor
Warn
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains instructions claiming a 'bypassPermissions' mode for writing to '.claude/' directories, which functions as an attempt to override platform security constraints.
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection. Ingestion points: '/tmp/.claude-task-outcomes' and '.claude/agent-memory'. Capability inventory: bash file reading and file generation. Boundary markers: Absent. Sanitization: Absent. This allows historical task data to influence the generation of new executable skill files.
- [COMMAND_EXECUTION]: The skill uses shell commands to access sensitive internal logs and agent memory artifacts stored in system temporary and configuration directories.
Audit Metadata