rules-create-global

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests external project documentation (PRDs, architecture specs, or codebase analyses) to derive its rules, which represents a potential surface for indirect prompt injection. If these source documents contain malicious instructions, they could be incorporated into the project's permanent steering files.\n
  • Ingestion points: Project documentation paths provided via the path1 and path2 arguments, as well as the conversation's primed codebase context.\n
  • Boundary markers: Absent. The instructions do not specify delimiters to segregate ingested content from the agent's instructions.\n
  • Capability inventory: The skill is capable of writing and modifying root-level configuration files (CLAUDE.md, AGENTS.md) and creating reference documentation in the .claude/ directory.\n
  • Sanitization: No specific sanitization or filtering logic is described for the content extracted from input files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 03:58 PM
Security Audit — agent-trust-hub — rules-create-global