learn-and-improve
Warn
Audited by Gen Agent Trust Hub on Apr 28, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill instructions direct the agent to read highly sensitive configuration files including ~/.claude/settings.json, ~/.claude.json, and various environment files. These files are standard locations for storing API keys, authentication tokens, and private system configuration data.
- [COMMAND_EXECUTION]: The skill is designed to modify security-critical settings to auto-allow shell commands and bypass permission prompts. It provides specific templates for setting up "hooks" and permissions rules that can permanently disable the platform's primary defense against unauthorized or dangerous tool execution.
- [PROMPT_INJECTION]: The "Verified Improvements" log (references/verified-improvements.md) serves as a persistent memory that the skill reads to influence its future logic and decision-making. This creates an indirect prompt injection surface where instructions or adversarial patterns from processed session data could be recorded and subsequently influence the agent's behavior in future contexts.
Audit Metadata