rules-distill
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local bash scripts (
scan-skills.shandscan-rules.sh) to perform a filesystem inventory. These scripts use standard Unix utilities likefind,grep,awk, andjqto parse metadata and headings from markdown files.\n- [DATA_EXFILTRATION]: The skill performs broad read access to sensitive directories containing the agent's instructions and logic (~/.claude/skillsand~/.claude/rules). Although no network communication is observed in the scripts, the aggregation of all system rules and skill content into the LLM context creates a significant data exposure surface.\n- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection from data ingested during the distillation process.\n - Ingestion points: Markdown content from all files in the skills and rules directories.\n
- Boundary markers: The subagent prompt uses basic text delimiters to separate content, which may be insufficient to prevent maliciously crafted principles from influencing the LLM.\n
- Capability inventory: Extensive file system read access and the ability to propose and apply modifications to system-level rule files.\n
- Sanitization: No validation or sanitization is performed on the ingested data before it is processed by the analysis subagent.
Audit Metadata