local-skills-sync
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local shell commands (bash, rsync, python3) to perform file synchronization and inventory management. These operations are targeted at the user's home directory (
/.claude/skills) and personal repository path (/personal/skills). - [INDIRECT_PROMPT_INJECTION]: The skill parses the content of SKILL.md files located in the local skills directory to suggest destination buckets. 1. Ingestion points: The agent is instructed to read SKILL.md descriptions, and the scripts/triage.py script identifies files for comparison. 2. Boundary markers: No specific delimiters are used when the agent reads the skill descriptions to suggest buckets. 3. Capability inventory: The skill can execute shell commands (bash, rsync), write to repository metadata files (marketplace.json, README.md), and create new directories. 4. Sanitization: No explicit sanitization of the SKILL.md content is performed before the agent processes it for decision-making.
Audit Metadata