plugin-settings

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPERSISTENCECOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documents a pattern for reading instructions and configuration from .claude/*.local.md files. This allows data in the project directory to influence agent behavior. Ingestion points include .claude/ files read in scripts such as read-settings-hook.sh and referenced in real-world-examples.md. Capabilities include the Bash, Read, and Write tools as seen in create-settings-command.md. Examples provide boundary markers (YAML frontmatter delimiters) and sanitization logic to block path traversal (..) and sensitive file access (.env, secrets).
  • [PERSISTENCE]: The skill documents the 'ralph-loop' pattern in real-world-examples.md, which prevents agent session termination by returning a block decision in hook output. This enables the creation of autonomous, recurring agent loops.
  • [COMMAND_EXECUTION]: Provides implementation patterns for using tmux send-keys to interact with other terminal sessions. As described in real-world-examples.md, target session names are retrieved from local configuration files, which could lead to unauthorized cross-session interaction if the configuration is maliciously altered.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 03:43 AM
Security Audit — agent-trust-hub — plugin-settings