rules-create-global
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill ingests external project documentation (PRDs, architecture specs, or codebase analyses) to derive its rules, which represents a potential surface for indirect prompt injection. If these source documents contain malicious instructions, they could be incorporated into the project's permanent steering files.\n
- Ingestion points: Project documentation paths provided via the
path1andpath2arguments, as well as the conversation's primed codebase context.\n - Boundary markers: Absent. The instructions do not specify delimiters to segregate ingested content from the agent's instructions.\n
- Capability inventory: The skill is capable of writing and modifying root-level configuration files (
CLAUDE.md,AGENTS.md) and creating reference documentation in the.claude/directory.\n - Sanitization: No specific sanitization or filtering logic is described for the content extracted from input files.
Audit Metadata