honest-agent

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPERSISTENCECOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill reads existing configuration files from the local project and global directories which may contain untrusted or malicious instructions.
  • Ingestion points: The skill reads .claude/CLAUDE.md, .github/copilot-instructions.md, .cursorrules, .windsurfrules, .clinerules, CONVENTIONS.md, .aider.conf.yml, and .continue/config.json (SKILL.md).
  • Boundary markers: The skill appends new directives to the end of existing files without using delimiters or specific instructions to the agent to disregard potentially malicious content already present in the file.
  • Capability inventory: The skill utilizes file system read and write capabilities to modify agent instructions.
  • Sanitization: No sanitization or validation of the input file content is performed before appending the new configuration blocks.
  • [PERSISTENCE]: The skill establishes persistent behavioral changes for multiple AI agents by modifying global configuration files in the user's home directory (e.g., ~/.claude/CLAUDE.md, ~/.cursor/rules/, ~/.aider.conf.yml). These changes persist across all projects and future agent sessions.
  • [COMMAND_EXECUTION]: The skill executes file system operations to scan the project environment and user home directory for configuration files and performs write operations to modify their content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:53 PM
Security Audit — agent-trust-hub — honest-agent