ck
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPERSISTENCE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill features an indirect prompt injection surface as it ingests project-level text files.
- Ingestion points: In
commands/init.mjsandcommands/migrate.mjs, the skill readsREADME.md,CLAUDE.md, and project configuration files to auto-populate metadata like project goals and technical stacks. - Boundary markers: Extracted content is displayed to the user for manual confirmation before being saved to the persistent context, which mitigates the risk of accidental instruction following.
- Capability inventory: The skill has the ability to write project state to the local filesystem and execute defined Node.js scripts via the agent's shell.
- Sanitization: Metadata extraction is constrained by regular expressions and string length limits (e.g., 120 characters for descriptions) to limit the influence of external content.
- [COMMAND_EXECUTION]: The skill performs local command execution to provide project insights.
- The scripts
commands/shared.mjsandhooks/session-start.mjsinvoke the localgitbinary (e.g.,git log,git diff) to summarize code changes and commit history since the previous session. - [PERSISTENCE]: The skill implements a persistence mechanism to maintain session continuity.
- It includes a
SessionStarthook (hooks/session-start.mjs) that users can register in their agent configuration. This hook automatically injects a compact project summary into the agent's context at the start of every session to ensure project-specific goals and status are retained across restarts.
Audit Metadata