settings-management

Warn

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDATA_EXFILTRATIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill documents configuration parameters that allow for arbitrary shell command execution during agent operation.
  • references/claude-settings.md identifies apiKeyHelper, statusLine, and fileSuggestion as settings that execute commands via /bin/sh or a shell environment.
  • references/codex-settings.md describes a hooks system ([[hooks.PreToolUse]]) that executes Python or shell commands during the tool execution lifecycle.
  • [PRIVILEGE_ESCALATION]: The instructions detail how to enable highly permissive operational modes that bypass standard security guardrails.
  • Claude Code's permissions.defaultMode can be set to bypassPermissions, which disables standard approval prompts for most operations.
  • Codex CLI's sandbox_mode can be set to danger-full-access, which removes the security sandbox and allows full system access.
  • [DATA_EXFILTRATION]: The skill focuses on the management of files containing sensitive information, including API keys and environment variables (.env, settings.json, config.toml).
  • OpenCode's configuration supports variable substitution using {file:path/to/file}, which automatically interpolates local file contents into strings. This creates a risk where sensitive file data could be inadvertently included in prompts sent to remote model providers.
  • [PERSISTENCE]: By documenting how to modify configuration hooks and helper scripts, the skill provides a mechanism for establishing persistent malicious behavior. Malicious commands added to these configuration files will execute automatically in future agent sessions without further user interaction.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a vulnerability surface where untrusted configuration files in a project directory can influence agent behavior.
  • Ingestion points: The agent is instructed to read settings from .claude/settings.json, .codex/config.toml, and opencode.json located within the current project directory.
  • Boundary markers: The instructions do not define boundary markers or warnings to ignore malicious instructions embedded in these project-level configuration files.
  • Capability inventory: The agent has capabilities for file system read/write and arbitrary command execution through the documented configuration hooks.
  • Sanitization: There is no mention of sanitization or validation logic to prevent project-level settings from overriding critical security configurations like sandbox enforcement.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 22, 2026, 02:48 AM
Security Audit — agent-trust-hub — settings-management