honest-agent
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPERSISTENCECOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill reads existing configuration files from the local project and global directories which may contain untrusted or malicious instructions.
- Ingestion points: The skill reads
.claude/CLAUDE.md,.github/copilot-instructions.md,.cursorrules,.windsurfrules,.clinerules,CONVENTIONS.md,.aider.conf.yml, and.continue/config.json(SKILL.md). - Boundary markers: The skill appends new directives to the end of existing files without using delimiters or specific instructions to the agent to disregard potentially malicious content already present in the file.
- Capability inventory: The skill utilizes file system read and write capabilities to modify agent instructions.
- Sanitization: No sanitization or validation of the input file content is performed before appending the new configuration blocks.
- [PERSISTENCE]: The skill establishes persistent behavioral changes for multiple AI agents by modifying global configuration files in the user's home directory (e.g.,
~/.claude/CLAUDE.md,~/.cursor/rules/,~/.aider.conf.yml). These changes persist across all projects and future agent sessions. - [COMMAND_EXECUTION]: The skill executes file system operations to scan the project environment and user home directory for configuration files and performs write operations to modify their content.
Audit Metadata