migrate-rules

Pass

Audited by Gen Agent Trust Hub on Apr 10, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches version metadata from the author's official GitHub repository to notify the user of available updates.
  • [COMMAND_EXECUTION]: Performs file system operations including creating the AGENTS.md file and deleting or modifying existing configuration files, contingent on user verification and approval.
  • [PROMPT_INJECTION]: Features an indirect prompt injection surface by reading and consolidating rules from various local configuration files.
  • Ingestion points: Local agent configuration files such as .cursorrules, CLAUDE.md, and .github/copilot-instructions.md.
  • Boundary markers: Absent from the prompt instructions.
  • Capability inventory: File creation/modification (AGENTS.md), file deletion, and .gitignore updates.
  • Sanitization: The skill provides a summary of discovered rules and requires explicit user approval before executing consolidation steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 10, 2026, 02:03 PM
Security Audit — agent-trust-hub — migrate-rules