settings

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute grep commands for parsing project documentation (.claude/docs/effects-map.md) to dynamically identify reserved settings.
  • [REMOTE_CODE_EXECUTION]: Sources an external shell script (.claude/hooks/yaml-helper.sh) to handle YAML parsing and logic. While this executes code outside the primary skill file, it is a project-local dependency intended for CCGS framework operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external configuration files that could potentially contain malicious instructions.
  • Ingestion points: Reads project.yaml and project.local.yaml via the Read tool and helper functions.
  • Boundary markers: Not explicitly defined in the prompt interpolation, but settings are validated against allowed enums.
  • Capability inventory: Includes Bash command execution and file modification via Write and Edit tools.
  • Sanitization: Employs schema validation (validate_enum_value) and mandatory user confirmation via AskUserQuestion for all write operations to mitigate unauthorized changes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:51 PM
Security Audit — agent-trust-hub — settings