linter-setup

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill includes meta-instructions such as 'Ignore Claude-specific mode-switch instructions' and 'Strict execution contract', which are used to override the agent's default operating procedures and ensure the skill's protocol is followed without deviation.
  • [COMMAND_EXECUTION]: The skill workflow includes researching and installing third-party development tools via package managers, which involves executing shell commands on the host system to modify the environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from repository files like 'plan.md' and architecture reports to identify the project's tech stack. This ingested content is used to drive subsequent research and configuration actions without sufficient isolation.
  • Ingestion points: plan.md, architecture-design reports, and tech-stack-comparison reports.
  • Boundary markers: Absent; the instructions do not include markers to delimit ingested data or warn the agent to ignore instructions embedded within these files.
  • Capability inventory: Software installation (shell commands), configuration file creation, CI/CD pipeline modification, and subagent spawning (spawn_agent).
  • Sanitization: Absent; the skill does not specify any validation or sanitization steps for the data extracted from repository files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 08:23 PM
Security Audit — agent-trust-hub — linter-setup