reclaude
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill reads and processes the contents of
CLAUDE.mdand configuration files (such aspackage.jsonorMakefile) to refactor them into new rules. This creates a surface where malicious instructions embedded in the project files could influence the agent's behavior during the refactoring process. - Ingestion points: Content is ingested from
CLAUDE.md,package.json, and local skill definitions in~/.claude/skills/workflow/SKILL.md. - Boundary markers: The instructions do not provide explicit delimiters or instructions to treat the file content as inert data, which may lead the agent to follow instructions contained within the text being refactored.
- Capability inventory: The skill is capable of reading project files and writing new documentation/rule files to the
.claude/rules/directory. - Sanitization: The skill lacks explicit sanitization steps to filter or escape instructions found within the input files before they are processed or rewritten.
Audit Metadata