skills/eugene-ee/affaan-m-ecc/ck/Gen Agent Trust Hub

ck

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPERSISTENCE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill features an indirect prompt injection surface as it ingests project-level text files.
  • Ingestion points: In commands/init.mjs and commands/migrate.mjs, the skill reads README.md, CLAUDE.md, and project configuration files to auto-populate metadata like project goals and technical stacks.
  • Boundary markers: Extracted content is displayed to the user for manual confirmation before being saved to the persistent context, which mitigates the risk of accidental instruction following.
  • Capability inventory: The skill has the ability to write project state to the local filesystem and execute defined Node.js scripts via the agent's shell.
  • Sanitization: Metadata extraction is constrained by regular expressions and string length limits (e.g., 120 characters for descriptions) to limit the influence of external content.
  • [COMMAND_EXECUTION]: The skill performs local command execution to provide project insights.
  • The scripts commands/shared.mjs and hooks/session-start.mjs invoke the local git binary (e.g., git log, git diff) to summarize code changes and commit history since the previous session.
  • [PERSISTENCE]: The skill implements a persistence mechanism to maintain session continuity.
  • It includes a SessionStart hook (hooks/session-start.mjs) that users can register in their agent configuration. This hook automatically injects a compact project summary into the agent's context at the start of every session to ensure project-specific goals and status are retained across restarts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — ck