rules-distill

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill reads the full text of all installed skills to identify cross-cutting principles, which introduces a surface where malicious instructions embedded in those files could attempt to manipulate the distillation process.
  • Ingestion points: Phase 2 in SKILL.md describes reading the full text of all skills and rule files for subagent analysis.
  • Boundary markers: The subagent prompt uses thematic headers for input sections but does not employ specific delimiters or instructions to ignore commands within the source text.
  • Capability inventory: The skill identifies scripts for scanning directories and has the functionality to write or revise rule files in ~/.claude/rules (Phase 3).
  • Sanitization: No explicit content sanitization or validation of the source text is performed before LLM processing.
  • Mitigation: The skill explicitly requires manual user approval, modification, or skipping for every proposed rule change, preventing automated filesystem modifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — rules-distill