claude-md-updater

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it summarizes untrusted data from the conversation history into the project's persistent context file (CLAUDE.md), which is loaded into future sessions. \n
  • Ingestion points: Analyzes conversation history for project updates (file: SKILL.md).\n
  • Boundary markers: Requires the agent to present a unified diff for explicit user approval before any write operation (file: SKILL.md).\n
  • Capability inventory: Proposes and performs write operations to the CLAUDE.md project file.\n
  • Sanitization: Instructs the agent to exclude transient information and follow strict categorization rules to maintain document integrity.\n- [SAFE]: The skill implements proactive security measures by explicitly instructing the agent to never persist sensitive values, tokens, or credentials, recommending references to storage locations instead of the secrets themselves.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 10:40 PM
Security Audit — agent-trust-hub — claude-md-updater