clj-skill-eval

Fail

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill explicitly advises the agent to use the --dangerously-skip-permissions flag when launching subagents via Claude Code. This flag is specifically designed to bypass the platform's security sandbox and permission prompts for sensitive operations (such as file system modification and network requests), enabling subagents to perform potentially dangerous tasks without user oversight.\n- [EXTERNAL_DOWNLOADS]: The setup instructions use the neil command-line tool to create project scaffolds and add dependencies from external sources (e.g., io.github.abogoyavlensky/clojure-stack-lite). This involves fetching and potentially executing code from non-whitelisted third-party repositories.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
May 15, 2026, 03:02 PM
Security Audit — agent-trust-hub — clj-skill-eval