settings
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to executegrepcommands for parsing project documentation (.claude/docs/effects-map.md) to dynamically identify reserved settings. - [REMOTE_CODE_EXECUTION]: Sources an external shell script (
.claude/hooks/yaml-helper.sh) to handle YAML parsing and logic. While this executes code outside the primary skill file, it is a project-local dependency intended for CCGS framework operations. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external configuration files that could potentially contain malicious instructions.
- Ingestion points: Reads
project.yamlandproject.local.yamlvia theReadtool and helper functions. - Boundary markers: Not explicitly defined in the prompt interpolation, but settings are validated against allowed enums.
- Capability inventory: Includes
Bashcommand execution and file modification viaWriteandEdittools. - Sanitization: Employs schema validation (
validate_enum_value) and mandatory user confirmation viaAskUserQuestionfor all write operations to mitigate unauthorized changes.
Audit Metadata