create-settings-command

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill implements a legitimate workflow for managing local settings. It gathers user preferences through controlled prompts and stores them in a project-specific hidden directory.
  • Evidence: The skill uses AskUserQuestion with defined options and the Write tool to create .claude/my-plugin.local.md.
  • [NO_CODE]: The skill consists exclusively of markdown instructions and does not ship with any scripts or executable code.
  • Evidence: The logic is contained entirely within the SKILL.md file, providing templates for agent behavior.
  • [SAFE]: While the skill writes user-provided data to a file (a potential indirect prompt injection surface), the implementation follows security best practices to mitigate risk.
  • Ingestion points: User input from the AskUserQuestion tool (SKILL.md).
  • Boundary markers: Input is constrained to specific multi-select labels (Yes/No, Strict/Standard/Lenient), preventing arbitrary text injection in the example.
  • Capability inventory: Uses the Write tool to create a local markdown file (SKILL.md).
  • Sanitization: Implementation notes explicitly instruct the agent to validate numeric fields, check for path traversal attempts, and sanitize any free-text fields before writing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 12:22 AM
Security Audit — agent-trust-hub — create-settings-command