skill-extractor

Warn

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions claiming a 'bypassPermissions' mode for writing to '.claude/' directories, which functions as an attempt to override platform security constraints.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection. Ingestion points: '/tmp/.claude-task-outcomes' and '.claude/agent-memory'. Capability inventory: bash file reading and file generation. Boundary markers: Absent. Sanitization: Absent. This allows historical task data to influence the generation of new executable skill files.
  • [COMMAND_EXECUTION]: The skill uses shell commands to access sensitive internal logs and agent memory artifacts stored in system temporary and configuration directories.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 18, 2026, 12:44 PM
Security Audit — agent-trust-hub — skill-extractor