project-init
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
node -eto execute several local JavaScript helper scripts (e.g.,session-init-helpers.cjs,agent-files-state.cjs,project-config-loader.cjs) to assess the folder classification and verify the project state. - [COMMAND_EXECUTION]: During the documentation normalization phase, the skill executes
git mvandgit rmcommands to reorganize files and resolve legacy naming conflicts within the repository. - [PROMPT_INJECTION]: The skill is subject to indirect prompt injection because it ingests and acts upon content from multiple untrusted project files.
- Ingestion points: Processes content from
docs/project-config.json,docs/project-reference/docs-index-reference.md,docs/project-reference/lessons.md,CLAUDE.md, andAGENTS.md(viaSKILL.mdPhase 0 and Phase 2). - Boundary markers: There are no explicit instructions or delimiters used to separate user-provided content from the agent's internal instructions when reading these files.
- Capability inventory: The skill has broad capabilities including shell command execution (
node,git), file system writes (git mv,git rm, updatingCLAUDE.md), and the ability to spawn sub-agents (spawn_agent). - Sanitization: The skill lacks sanitization or validation of the text content ingested from these documentation files before it influences the agent's routing and planning decisions.
Audit Metadata