clean-code

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains a 'Verification Scripts' section that mandates the execution of multiple Python scripts (e.g., ux_audit.py, security_scan.py, lint_runner.py) using the python CLI. These scripts are located in external paths outside the skill's own directory structure (~/.claude/skills/...), representing a dependency on external, unverified code.
  • [INDIRECT_PROMPT_INJECTION]: The 'Script Output Handling' section instructs the agent to 'capture ALL output' and 'parse the output' to identify errors and warnings. This process involves ingesting untrusted data from external script executions into the agent's context without the use of sanitization, filtering, or clear boundary markers to prevent embedded instructions from influencing the agent's behavior.
  • Ingestion points: Verification script outputs (stdout/stderr).
  • Boundary markers: Absent. The instructions do not specify delimiters or 'ignore' instructions for the captured output.
  • Capability inventory: The skill utilizes Read, Write, and Edit tools, and attempts to invoke python via shell for script execution.
  • Sanitization: Absent. The agent is directed to parse and summarize the raw output directly.
  • [PROMPT_INJECTION]: The skill uses high-pressure directives ('CRITICAL', 'MANDATORY', '🔴 Rule') and commands the agent to suppress standard conversational behavior ('Fix it, don't explain', 'The user wants working code, not a programming lesson'). While aimed at efficiency, these instructions attempt to override the agent's default helpfulness and transparency protocols.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — clean-code