sync-skills-shared-protocols
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains instructions that explicitly command the agent to override or ignore platform-specific behaviors, specifically: 'Ignore Claude-specific mode-switch instructions when they appear'. This is a direct attempt to control the agent's internal operational state beyond the immediate task.
- [COMMAND_EXECUTION]: The skill automates bulk modifications to the repository's instruction files using shell commands (
grep) and a local Python script (.claude/scripts/sync-hooks-to-skills.py). While these tools are local, the automation of large-scale edits to the agent's own instruction set represents a high-impact capability. - [INDIRECT_PROMPT_INJECTION]: The skill functions as a vector for content propagation across the entire instruction set of the agent (targeting over 180 files).
- Ingestion points: The skill reads external content from
.claude/skills/shared/sync-inline-versions.mdand scans allSKILL.mdand agent.mdfiles in the repository. - Boundary markers: It relies on HTML comments (
<!-- SYNC:tag -->) to identify injection sites. While these provide structure, they do not provide security isolation or validation of the content being moved. - Capability inventory: The skill has the capability to perform bulk file writes, execute
grepfor file discovery, and run thesync-hooks-to-skills.pyscript which controls the propagation logic. - Sanitization: There is no evidence of sanitization, filtering, or validation of the synced content. If a source file is compromised with malicious instructions within a SYNC block, the skill will automatically distribute those instructions across all other skills and agents in the environment.
Audit Metadata