skills/iwasa-kosui/kamae-ts/kamae/Gen Agent Trust Hub

kamae

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill configuration directs the AI agent to automatically discover and adhere to instructions found in locally available rule files (.claude/rules/*.md). This creates a vulnerability where a malicious project could influence or override the agent's behavior and safety protocols through committed configuration files.
  • Ingestion points: The skill glob paths include .claude/rules/*.md within the working tree and user home directory.
  • Boundary markers: The instructions fail to define clear boundaries or sanitization steps for the rule content, stating that the agent should "Apply the body of each surviving rule throughout the remaining steps."
  • Capability inventory: The skill allows the agent to refine domain logic, handle PII (Personally Identifiable Information), and design error handling. Malicious rules could potentially be used to extract sensitive business logic or weaken the described PII protection mechanisms.
  • Sanitization: There is no evidence of sanitization or content validation for the rules loaded from the local file system.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:33 AM
Security Audit — agent-trust-hub — kamae