config-gc

Warn

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill accesses sensitive configuration files that manage agent permissions and execution settings.\n
  • Files targeted include ~/.claude/settings.json, ~/.claude/settings.local.json, and ~/.claude/permissions.allow.\n
  • The skill is designed to read, duplicate for backup, and modify these files to remove redundant permission entries using shell utilities.\n- [COMMAND_EXECUTION]: The skill provided instructions include multiple bash command blocks intended for execution by the agent to perform system audits and file operations.\n
  • The shell commands utilize tools such as grep for searching configuration files, jq for manipulating JSON permission structures, and find/du for identifying large or stale files.\n
  • File system modifications are performed via cp for backups and mv for soft-deletion (moving items to a trash directory).\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external files which could be manipulated by an attacker to include hidden instructions that influence the agent's behavior during the cleanup workflow.\n
  • Ingestion points: The agent is instructed to read content from SKILL.md files within ~/.claude/skills/ and markdown files within ~/.claude/**/memory/ to identify redundancy and staleness.\n
  • Boundary markers: Absent. There are no instructions for the agent to use specific delimiters or to disregard natural language instructions found within the data being scanned.\n
  • Capability inventory: The skill provides the agent with capabilities to modify permissions, move or rename files, and execute shell commands based on findings from the ingested data.\n
  • Sanitization: Absent. The skill does not implement validation or filtering for the content retrieved from the external skill or memory files.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 12, 2026, 03:39 PM
Security Audit — agent-trust-hub — config-gc