rules-distill
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill reads the full text of all installed skills to identify cross-cutting principles, which introduces a surface where malicious instructions embedded in those files could attempt to manipulate the distillation process.
- Ingestion points: Phase 2 in SKILL.md describes reading the full text of all skills and rule files for subagent analysis.
- Boundary markers: The subagent prompt uses thematic headers for input sections but does not employ specific delimiters or instructions to ignore commands within the source text.
- Capability inventory: The skill identifies scripts for scanning directories and has the functionality to write or revise rule files in ~/.claude/rules (Phase 3).
- Sanitization: No explicit content sanitization or validation of the source text is performed before LLM processing.
- Mitigation: The skill explicitly requires manual user approval, modification, or skipping for every proposed rule change, preventing automated filesystem modifications.
Audit Metadata