skill-stocktake
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is designed to execute several local bash scripts (
scan.sh,quick-diff.sh, andsave-results.sh) to perform file system tasks such as directory scanning, mtime comparison, and JSON results merging. These scripts use standard command-line utilities likejq,awk, andfindwith quoted arguments to prevent common shell injection vulnerabilities.\n- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because its primary function involves reading and evaluating the content of other AI skills. Maliciously crafted skills could attempt to override the auditor's judgment.\n - Ingestion points: The
scan.shscript and Phase 2 evaluation logic read all markdown files in both global (~/.claude/skills/) and project-local (.claude/skills/) directories.\n - Boundary markers: The skill prompt uses explicit
[INVENTORY]and[CHECKLIST]delimiters to separate external data from its evaluation instructions, which mitigates but does not fully eliminate injection risks.\n - Capability inventory: The skill has the capability to run local shell scripts, write to the user's home directory (results cache), and trigger subagents with broad reasoning capabilities.\n
- Sanitization: While the
scan.shscript usesawkfor structured metadata extraction, the full content of audited files is passed to the AI subagent without extensive sanitization.
Audit Metadata