claude-md-updater

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes conversation context to extract information for persistence, creating a surface for indirect prompt injection where untrusted session data could attempt to influence the content of the project's documentation.
  • Ingestion points: The agent context is scanned for durability-related keywords as instructed in SKILL.md.
  • Boundary markers: A unified diff is presented to the user, and the skill explicitly requires approval before any file writes occur.
  • Capability inventory: The skill facilitates modifications to the local CLAUDE.md file.
  • Sanitization: No specific automated filtering is mentioned; the security model relies on human review of the suggested diff.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 11:22 PM
Security Audit — agent-trust-hub — claude-md-updater