strategic-compact

Warn

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPERSISTENCEREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs users to configure their environment to execute a Node.js script (node ~/.claude/scripts/hooks/suggest-compact.js) during tool invocations. This encourages the execution of code outside the skill's own package boundary.
  • [REMOTE_CODE_EXECUTION]: The skill's primary functionality relies on the existence of an external script, suggest-compact.js, which is not provided in the skill contents. This establishes a dependency on an unverifiable external file that may not exist or could contain unvetted code.
  • [PERSISTENCE]: The skill provides configuration blocks intended for the global ~/.claude/settings.json file. Implementing these changes creates a persistent execution hook that triggers the external script every time the agent uses 'Edit' or 'Write' tools in any future session.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 12, 2026, 03:41 PM
Security Audit — agent-trust-hub — strategic-compact