skill-stocktake

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed to execute several local bash scripts (scan.sh, quick-diff.sh, and save-results.sh) to perform file system tasks such as directory scanning, mtime comparison, and JSON results merging. These scripts use standard command-line utilities like jq, awk, and find with quoted arguments to prevent common shell injection vulnerabilities.\n- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because its primary function involves reading and evaluating the content of other AI skills. Maliciously crafted skills could attempt to override the auditor's judgment.\n
  • Ingestion points: The scan.sh script and Phase 2 evaluation logic read all markdown files in both global (~/.claude/skills/) and project-local (.claude/skills/) directories.\n
  • Boundary markers: The skill prompt uses explicit [INVENTORY] and [CHECKLIST] delimiters to separate external data from its evaluation instructions, which mitigates but does not fully eliminate injection risks.\n
  • Capability inventory: The skill has the capability to run local shell scripts, write to the user's home directory (results cache), and trigger subagents with broad reasoning capabilities.\n
  • Sanitization: While the scan.sh script uses awk for structured metadata extraction, the full content of audited files is passed to the AI subagent without extensive sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 03:42 AM
Security Audit — agent-trust-hub — skill-stocktake