clean-code
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The 'Verification Scripts' section instructs the agent to execute specific Python scripts located in diverse subdirectories within
~/.claude/skills/(e.g.,vulnerability-scanner,api-patterns,seo-fundamentals). This extends the skill's reach to trigger code execution from multiple external local directories, rather than limiting it to its own resources. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and modify user-supplied source code, which is then provided as an argument to the validation scripts.
- Ingestion points: The current directory (
.) and user-provided URLs are passed directly to the scripts (e.g.,lighthouse_audit.py <url>). - Boundary markers: There are no instructions to use delimiters or ignore directives for the content of the files being analyzed.
- Capability inventory: The skill facilitates the execution of Python scripts via the shell, which can access the local filesystem.
- Sanitization: No validation or sanitization steps are defined for the input arguments or the content of the files processed by the scripts.
- [DYNAMIC_EXECUTION]: The skill relies on the execution of Python scripts located at absolute paths on the filesystem to perform verification, creating a dependency on the integrity and behavior of external local code that is not contained within the skill itself.
Audit Metadata