document

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is designed to ingest and process documentation files from the project repository.
  • Ingestion points: The skill reads several files including PRODUCT.md, README.md, PROMPTS.md, NOTES.md, and FRICTION.md into the agent's context (SKILL.md).
  • Boundary markers: While the skill uses markers like (finding: for content filtering, it does not employ explicit boundary delimiters to prevent the agent from potentially executing instructions embedded within these files.
  • Capability inventory: The agent is instructed to read and write files, and execute shell commands for version tracking and project reconciliation (SKILL.md).
  • Sanitization: The skill performs a sanitization sweep focused on removing internal data from public-facing outputs, but lacks specific input sanitization to neutralize malicious instructions.
  • [COMMAND_EXECUTION]: The skill contains a shell command block for daily version checks. The command uses standard utilities like find, mkdir, curl, and touch to manage a rate-limiting timestamp in the ~/.claude/ directory.
  • [EXTERNAL_DOWNLOADS]: The skill fetches configuration documentation from the vendor's official GitHub repository and performs a version check against a vendor-owned domain.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 05:48 PM
Security Audit — agent-trust-hub — document