configure-skilllord
Warn
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill clones a remote repository from https://github.com/affaan-m/claude-skill-lord.git to a temporary directory on the local system. This source provides the skills and rules that are integrated into the agent's environment.
- [COMMAND_EXECUTION]: The skill executes multiple shell commands to manage the deployment process, including git clone for fetching resources, mkdir -p for directory setup, cp -r for deploying skill components, and rm -rf for cleaning up source files after installation.
- [DATA_EXPOSURE]: As part of its verification and optimization steps, the skill reads and scans files in the agent's sensitive configuration directory (~/.claude/) to identify path references and ensure consistency.
- [INDIRECT_PROMPT_INJECTION]: The skill acts as a delivery mechanism for external agent instructions. If the remote repository is compromised or contains malicious prompts, these would be directly integrated into the agent's future behavior and execution context.
Audit Metadata