claude-automation-recommender

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: Uses shell commands such as ls, cat, and grep during the discovery phase to analyze the codebase. These commands are used to identify the project's language, framework, dependencies, and existing configurations.
  • [EXTERNAL_DOWNLOADS]: Recommends the addition of external Model Context Protocol (MCP) servers and plugins. These recommendations target established platforms and well-known technology services, including GitHub, AWS, Cloudflare, Supabase, and Sentry.
  • [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect injection as it processes untrusted data from the project's environment to generate recommendations.
  • Ingestion points: Reads project configuration files (e.g., package.json, pyproject.toml) and directory structures using Bash and Read tools in SKILL.md and referenced templates.
  • Boundary markers: None identified; the skill assumes the integrity of the files it analyzes.
  • Capability inventory: Includes Read, Glob, Grep, and Bash tool access.
  • Sanitization: No specific sanitization or filtering of file content is performed before analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — claude-automation-recommender