inherit-legacy-style
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands including
git ls-files,git diff, andgit logvia theBashtool to analyze project structure and track style evolution across commits. These are standard operations for codebase management. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data by scanning the project's source files to extract implicit coding conventions. Maliciously crafted comments or code structures could influence the resulting
.ai-style-rules.mdfile, which then acts as a behavioral constraint on the agent for all subsequent tasks. - Ingestion points: Source files (
.js,.py,.go, etc.),git log, andgit diffoutput. - Boundary markers: The skill does not define specific boundary markers to distinguish between legitimate code and potentially malicious instructions embedded within the scanned files.
- Capability inventory: The skill has
WriteandEditpermissions for project files andBashfor command execution. - Sanitization: No explicit sanitization or validation of the extracted stylistic patterns is mentioned before they are codified into rules.
- [PERSISTENCE]: The skill offers a 'Hard hook' option which involves writing a
PreToolUsehook to the agent'ssettings.json. While this is intended for rule enforcement, it modifies the agent's global configuration to persist the skill's logic across future sessions. This action is gated by theAskUserQuestiontool for user consent.
Audit Metadata