extract
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
Bashtool to executegrepandsed. These commands are used to calculate file paths and search through the project's memory directory based on the user's current working directory. - [DATA_EXFILTRATION]: The skill accesses sensitive file paths within the
$HOME/.claude/projects/directory. This location contains project-specific conversation histories and memory files that may include proprietary information or sensitive code snippets. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection when processing historical project data.
- Ingestion points: Data is ingested from the project's memory directory via
grepin Step 1 ofSKILL.md. - Boundary markers: No explicit delimiters or instructions are provided to distinguish between the skill's core instructions and the potentially untrusted content retrieved from memory.
- Capability inventory: The skill has access to the filesystem through file-writing tools and can execute shell commands via
Bash. - Sanitization: There is no evidence of sanitization, filtering, or validation of the content extracted from the project memory files before it is processed by the AI agent.
Audit Metadata