clean-code

Warn

Audited by Gen Agent Trust Hub on Mar 18, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill mandates the execution of multiple Python scripts located in the ~/.claude/skills/ directory (e.g., vulnerability-scanner/scripts/security_scan.py, testing-patterns/scripts/test_runner.py) after task completion. These scripts are external to the skill's source and are executed as subprocesses.
  • [COMMAND_EXECUTION]: The execution pattern for scripts like lighthouse_audit.py and playwright_runner.py involves passing a <url> parameter. If this URL is sourced from untrusted user input without strict sanitization, it presents a risk of command injection into the shell or the underlying Python script.
  • [PROMPT_INJECTION]: The skill instructions to "Write it directly" and "Fix it, don't explain" when handling user feature requests or bug reports create a risk of the agent being manipulated by malicious instructions embedded in the data it processes (Indirect Prompt Injection).
  • Ingestion points: Project source files and user-reported bug details processed via the 'Read', 'Write', and 'Edit' tools.
  • Boundary markers: No specific delimiters or safety instructions are provided to separate untrusted data from the agent's core instructions.
  • Capability inventory: File system modification (Write/Edit) and execution of arbitrary Python scripts from the local environment.
  • Sanitization: No sanitization, escaping, or validation logic is defined for the external content before it is processed or used as script arguments.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 18, 2026, 07:46 AM
Security Audit — agent-trust-hub — clean-code