plugin-settings
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPERSISTENCECOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents a pattern for reading instructions and configuration from .claude/*.local.md files. This allows data in the project directory to influence agent behavior. Ingestion points include .claude/ files read in scripts such as read-settings-hook.sh and referenced in real-world-examples.md. Capabilities include the Bash, Read, and Write tools as seen in create-settings-command.md. Examples provide boundary markers (YAML frontmatter delimiters) and sanitization logic to block path traversal (..) and sensitive file access (.env, secrets).
- [PERSISTENCE]: The skill documents the 'ralph-loop' pattern in real-world-examples.md, which prevents agent session termination by returning a block decision in hook output. This enables the creation of autonomous, recurring agent loops.
- [COMMAND_EXECUTION]: Provides implementation patterns for using tmux send-keys to interact with other terminal sessions. As described in real-world-examples.md, target session names are retrieved from local configuration files, which could lead to unauthorized cross-session interaction if the configuration is maliciously altered.
Audit Metadata