document
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is designed to ingest and process documentation files from the project repository.
- Ingestion points: The skill reads several files including
PRODUCT.md,README.md,PROMPTS.md,NOTES.md, andFRICTION.mdinto the agent's context (SKILL.md). - Boundary markers: While the skill uses markers like
(finding:for content filtering, it does not employ explicit boundary delimiters to prevent the agent from potentially executing instructions embedded within these files. - Capability inventory: The agent is instructed to read and write files, and execute shell commands for version tracking and project reconciliation (SKILL.md).
- Sanitization: The skill performs a sanitization sweep focused on removing internal data from public-facing outputs, but lacks specific input sanitization to neutralize malicious instructions.
- [COMMAND_EXECUTION]: The skill contains a shell command block for daily version checks. The command uses standard utilities like
find,mkdir,curl, andtouchto manage a rate-limiting timestamp in the~/.claude/directory. - [EXTERNAL_DOWNLOADS]: The skill fetches configuration documentation from the vendor's official GitHub repository and performs a version check against a vendor-owned domain.
Audit Metadata