policy
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the local script
bun scripts/policy-validate.tsto validate policy rules. This execution is part of the skill's internal validation workflow to ensure policy integrity. - [INDIRECT_PROMPT_INJECTION]: The skill modifies security policies based on user input, creating a potential surface for indirect prompt injection.
- Ingestion points: The
json-matchcommand argument and the existingaccess.jsonfile content. - Boundary markers: The skill relies on JSON parsing rather than explicit prompt delimiters to separate data from instructions.
- Capability inventory: Capabilities include reading and writing the
access.jsonconfiguration and executing local scripts. - Sanitization: The skill validates that input is well-formed JSON and uses an external script to verify the resulting policy schema.
- [CREDENTIALS_UNSAFE]: The skill reads from and writes to
~/.claude/channels/slack/access.json, which contains sensitive pairing codes and access control lists. This access is necessary for the skill's primary function of policy management.
Audit Metadata