clean-code
Warn
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill mandates the execution of multiple Python scripts located in the
~/.claude/skills/directory (e.g.,vulnerability-scanner/scripts/security_scan.py,testing-patterns/scripts/test_runner.py) after task completion. These scripts are external to the skill's source and are executed as subprocesses. - [COMMAND_EXECUTION]: The execution pattern for scripts like
lighthouse_audit.pyandplaywright_runner.pyinvolves passing a<url>parameter. If this URL is sourced from untrusted user input without strict sanitization, it presents a risk of command injection into the shell or the underlying Python script. - [PROMPT_INJECTION]: The skill instructions to "Write it directly" and "Fix it, don't explain" when handling user feature requests or bug reports create a risk of the agent being manipulated by malicious instructions embedded in the data it processes (Indirect Prompt Injection).
- Ingestion points: Project source files and user-reported bug details processed via the 'Read', 'Write', and 'Edit' tools.
- Boundary markers: No specific delimiters or safety instructions are provided to separate untrusted data from the agent's core instructions.
- Capability inventory: File system modification (Write/Edit) and execution of arbitrary Python scripts from the local environment.
- Sanitization: No sanitization, escaping, or validation logic is defined for the external content before it is processed or used as script arguments.
Audit Metadata