inherit-legacy-style

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands including git ls-files, git diff, and git log via the Bash tool to analyze project structure and track style evolution across commits. These are standard operations for codebase management.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data by scanning the project's source files to extract implicit coding conventions. Maliciously crafted comments or code structures could influence the resulting .ai-style-rules.md file, which then acts as a behavioral constraint on the agent for all subsequent tasks.
  • Ingestion points: Source files (.js, .py, .go, etc.), git log, and git diff output.
  • Boundary markers: The skill does not define specific boundary markers to distinguish between legitimate code and potentially malicious instructions embedded within the scanned files.
  • Capability inventory: The skill has Write and Edit permissions for project files and Bash for command execution.
  • Sanitization: No explicit sanitization or validation of the extracted stylistic patterns is mentioned before they are codified into rules.
  • [PERSISTENCE]: The skill offers a 'Hard hook' option which involves writing a PreToolUse hook to the agent's settings.json. While this is intended for rule enforcement, it modifies the agent's global configuration to persist the skill's logic across future sessions. This action is gated by the AskUserQuestion tool for user consent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — inherit-legacy-style