strategic-compact
Warn
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPERSISTENCEREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs users to configure their environment to execute a Node.js script (
node ~/.claude/scripts/hooks/suggest-compact.js) during tool invocations. This encourages the execution of code outside the skill's own package boundary. - [REMOTE_CODE_EXECUTION]: The skill's primary functionality relies on the existence of an external script,
suggest-compact.js, which is not provided in the skill contents. This establishes a dependency on an unverifiable external file that may not exist or could contain unvetted code. - [PERSISTENCE]: The skill provides configuration blocks intended for the global
~/.claude/settings.jsonfile. Implementing these changes creates a persistent execution hook that triggers the external script every time the agent uses 'Edit' or 'Write' tools in any future session.
Audit Metadata