skill-logger

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill captures and stores full user queries in a local SQLite database (~/.claude/skill_logs.db) as shown in the implementation guide in SKILL.md. This practice can lead to the unintended exposure of sensitive data, such as credentials or private information, if they were included in the original prompts.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input through its logging and analytical functions, creating a potential vector for injection attacks.
  • Ingestion points: Data is ingested from user_query, skill output, and tool_calls as defined in the logging architecture in SKILL.md and references/scoring-rubric.md.
  • Boundary markers: No specific delimiters or safety instructions are present in the code snippets to distinguish between instructions and logged data.
  • Capability inventory: The skill is granted access to the Bash, Write, Edit, and Read tools, providing significant system access.
  • Sanitization: The provided Python logic for processing logs does not include sanitization or filtering of the captured content.
  • [COMMAND_EXECUTION]: The skill requests permission to use the Bash tool. While intended for database management and analytics as described in SKILL.md, this capability could be misused to execute arbitrary commands if malicious content is processed from the logs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 10:09 PM
Security Audit — agent-trust-hub — skill-logger