settings-management
Warn
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDATA_EXFILTRATIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill documents configuration parameters that allow for arbitrary shell command execution during agent operation.
references/claude-settings.mdidentifiesapiKeyHelper,statusLine, andfileSuggestionas settings that execute commands via/bin/shor a shell environment.references/codex-settings.mddescribes ahookssystem ([[hooks.PreToolUse]]) that executes Python or shell commands during the tool execution lifecycle.- [PRIVILEGE_ESCALATION]: The instructions detail how to enable highly permissive operational modes that bypass standard security guardrails.
- Claude Code's
permissions.defaultModecan be set tobypassPermissions, which disables standard approval prompts for most operations. - Codex CLI's
sandbox_modecan be set todanger-full-access, which removes the security sandbox and allows full system access. - [DATA_EXFILTRATION]: The skill focuses on the management of files containing sensitive information, including API keys and environment variables (
.env,settings.json,config.toml). - OpenCode's configuration supports variable substitution using
{file:path/to/file}, which automatically interpolates local file contents into strings. This creates a risk where sensitive file data could be inadvertently included in prompts sent to remote model providers. - [PERSISTENCE]: By documenting how to modify configuration hooks and helper scripts, the skill provides a mechanism for establishing persistent malicious behavior. Malicious commands added to these configuration files will execute automatically in future agent sessions without further user interaction.
- [INDIRECT_PROMPT_INJECTION]: The skill identifies a vulnerability surface where untrusted configuration files in a project directory can influence agent behavior.
- Ingestion points: The agent is instructed to read settings from
.claude/settings.json,.codex/config.toml, andopencode.jsonlocated within the current project directory. - Boundary markers: The instructions do not define boundary markers or warnings to ignore malicious instructions embedded in these project-level configuration files.
- Capability inventory: The agent has capabilities for file system read/write and arbitrary command execution through the documented configuration hooks.
- Sanitization: There is no mention of sanitization or validation logic to prevent project-level settings from overriding critical security configurations like sandbox enforcement.
Audit Metadata