rules-distill

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local bash scripts (scan-skills.sh and scan-rules.sh) to perform a filesystem inventory. These scripts use standard Unix utilities like find, grep, awk, and jq to parse metadata and headings from markdown files.\n- [DATA_EXFILTRATION]: The skill performs broad read access to sensitive directories containing the agent's instructions and logic (~/.claude/skills and ~/.claude/rules). Although no network communication is observed in the scripts, the aggregation of all system rules and skill content into the LLM context creates a significant data exposure surface.\n- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection from data ingested during the distillation process.\n
  • Ingestion points: Markdown content from all files in the skills and rules directories.\n
  • Boundary markers: The subagent prompt uses basic text delimiters to separate content, which may be insufficient to prevent maliciously crafted principles from influencing the LLM.\n
  • Capability inventory: Extensive file system read access and the ability to propose and apply modifications to system-level rule files.\n
  • Sanitization: No validation or sanitization is performed on the ingested data before it is processed by the analysis subagent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 03:43 AM
Security Audit — agent-trust-hub — rules-distill