configure-ecc
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill clones the Everything Claude Code project from a public GitHub repository (github.com/affaan-m/everything-claude-code.git) into a temporary directory to source installation files.
- [COMMAND_EXECUTION]: The skill uses shell commands including 'git clone', 'cp -r', 'rm -rf', and 'mkdir' to handle the deployment and cleanup of new agent components on the local file system.
- [PERSISTENCE]: The skill creates persistent changes to the agent's execution environment by installing new skills and rules into the global and project-level configuration directories (~/.claude/skills/ and ~/.claude/rules/).
- [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect injection as it ingests and processes external content from a remote repository. It provides no sanitization for user-provided 'Other' skill names which are interpolated into shell copy commands. 1. Ingestion points: File system via 'git clone' and 'AskUserQuestion' inputs (SKILL.md). 2. Boundary markers: None. 3. Capability inventory: 'cp', 'rm', 'git clone', 'mkdir', 'grep', and 'ls' (SKILL.md). 4. Sanitization: None identified.
- [DYNAMIC_EXECUTION]: The skill performs runtime modification of agent instructions in Step 5 by reading, editing, and overwriting SKILL.md and rule files in the target installation directory to 'optimize' them for the user's stack.
Audit Metadata