claude
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is centered around executing the
claudeCLI sub-agent. This command-line tool has capabilities for network access and file system modification within the working tree.\n- [PRIVILEGE_ESCALATION]: The instructions include the use of the--dangerously-skip-permissionsflag for broad autonomous tasks. This flag bypasses interactive permission prompts, granting the sub-agent higher autonomy than typical restricted executions.\n- [INDIRECT_PROMPT_INJECTION]: The skill defines a multi-agent workflow where the primary agent ingests and acts upon output generated by a sub-agent. This creates a vulnerability to indirect injection if the sub-agent processes malicious data or generates deceptive outputs.\n - Ingestion points: The primary agent reads the output of the
claude -pshell command.\n - Boundary markers: The skill recommends using explicit XML-like tags (e.g.,
<task>,<output_contract>) to delimit instructions for the sub-agent.\n - Capability inventory: The sub-agent tool possesses capabilities for reading/writing files and executing bash commands.\n
- Sanitization: The instructions explicitly mandate that the primary agent must 'verify its claims', 'inspect the diff', and 'triage every finding' before relaying or acting on results.
Audit Metadata