claude-md-updater
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes conversation context to extract information for persistence, creating a surface for indirect prompt injection where untrusted session data could attempt to influence the content of the project's documentation.
- Ingestion points: The agent context is scanned for durability-related keywords as instructed in
SKILL.md. - Boundary markers: A unified diff is presented to the user, and the skill explicitly requires approval before any file writes occur.
- Capability inventory: The skill facilitates modifications to the local
CLAUDE.mdfile. - Sanitization: No specific automated filtering is mentioned; the security model relies on human review of the suggested diff.
Audit Metadata