dcg
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill relies on the
dcg(destructive_command_guard) binary. The validation script (scripts/validate-dcg.sh) directs users to download and install this tool from an unverified GitHub repository (github.com/Dicklesworthstone/destructive_command_guard). - [COMMAND_EXECUTION]: The skill frequently executes the
dcgCLI tool with various subcommands (doctor,explain,test,scan,packs) to inspect the environment and evaluate command safety. It also instructions the agent to execute alternative commands likegit stashorgit push --force-with-leasewhen standard destructive commands are blocked. - [PRIVILEGE_ESCALATION]: The skill references commands that perform system-level modifications. The
dcg doctoroutput (inreferences/COMMANDS.md) indicates the binary resides in/usr/local/bin/, anddcg install(referenced inreferences/TROUBLESHOOTING.md) modifies the agent's configuration file at~/.claude/settings.jsonto register execution hooks. Thedcg updatecommand also facilitates binary replacement. - [PERSISTENCE]: The skill provides functionality to install persistent scripts, specifically git pre-commit hooks (
dcg scan install-pre-commitinreferences/COMMANDS.md), which automatically execute the scanner before each commit to the repository. - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes untrusted command strings and repository content. While it emphasizes safety and human approval, the reliance on an external tool for parsing complex scripts presents a potential vector.
- Ingestion points: Repository files scanned by
dcg scan(references/COMMANDS.md), command strings passed todcg explain(SKILL.md), and content of heredocs/inline scripts processed by the AST parser (references/CONFIG.md). - Boundary markers: The skill instructs the agent to use
dcg explainto verify the reason for a block and present this trace to the user, acting as a functional boundary before any bypass is considered (SKILL.md). - Capability inventory: Subprocess calls for
dcg,git,kubectl,rm, and other CLI tools across all instruction files, plus filesystem writes for configuration files (.dcg.toml). - Sanitization: The
dcgtool performs normalization and context sanitization during its evaluation pipeline (SKILL.md), although the robustness against adversarial content is dependent on the external binary's implementation.
Audit Metadata