project-init

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses node -e to execute several local JavaScript helper scripts (e.g., session-init-helpers.cjs, agent-files-state.cjs, project-config-loader.cjs) to assess the folder classification and verify the project state.
  • [COMMAND_EXECUTION]: During the documentation normalization phase, the skill executes git mv and git rm commands to reorganize files and resolve legacy naming conflicts within the repository.
  • [PROMPT_INJECTION]: The skill is subject to indirect prompt injection because it ingests and acts upon content from multiple untrusted project files.
  • Ingestion points: Processes content from docs/project-config.json, docs/project-reference/docs-index-reference.md, docs/project-reference/lessons.md, CLAUDE.md, and AGENTS.md (via SKILL.md Phase 0 and Phase 2).
  • Boundary markers: There are no explicit instructions or delimiters used to separate user-provided content from the agent's internal instructions when reading these files.
  • Capability inventory: The skill has broad capabilities including shell command execution (node, git), file system writes (git mv, git rm, updating CLAUDE.md), and the ability to spawn sub-agents (spawn_agent).
  • Sanitization: The skill lacks sanitization or validation of the text content ingested from these documentation files before it influences the agent's routing and planning decisions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 08:23 PM
Security Audit — agent-trust-hub — project-init