policy

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the local script bun scripts/policy-validate.ts to validate policy rules. This execution is part of the skill's internal validation workflow to ensure policy integrity.
  • [INDIRECT_PROMPT_INJECTION]: The skill modifies security policies based on user input, creating a potential surface for indirect prompt injection.
  • Ingestion points: The json-match command argument and the existing access.json file content.
  • Boundary markers: The skill relies on JSON parsing rather than explicit prompt delimiters to separate data from instructions.
  • Capability inventory: Capabilities include reading and writing the access.json configuration and executing local scripts.
  • Sanitization: The skill validates that input is well-formed JSON and uses an external script to verify the resulting policy schema.
  • [CREDENTIALS_UNSAFE]: The skill reads from and writes to ~/.claude/channels/slack/access.json, which contains sensitive pairing codes and access control lists. This access is necessary for the skill's primary function of policy management.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 11:06 AM
Security Audit — agent-trust-hub — policy