skills/grupous/gpus/clean-code/Gen Agent Trust Hub

clean-code

Warn

Audited by Gen Agent Trust Hub on Apr 24, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill mandates the execution of various Python scripts located in paths outside of the skill's own package (e.g., python ~/.claude/skills/vulnerability-scanner/scripts/security_scan.py .). This introduces a dependency on external executable code that is not bundled with the skill.
  • [PROMPT_INJECTION]: The skill uses authoritative directives to override default agent behavior, specifically instructing the AI to suppress explanations ('Fix it, don't explain', 'Just write code') and to bypass standard communication patterns, which can lead to automated changes without adequate user review.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 24, 2026, 09:21 AM
Security Audit — agent-trust-hub — clean-code