skills/jhostalek/dotclaude/audit-perf/Gen Agent Trust Hub

audit-perf

Warn

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The SKILL.md file contains a dynamic context injection pattern (!cat ...) that executes a shell command during the skill loading phase, allowing for automated execution without user oversight.
  • [DATA_EXFILTRATION]: The command specifically targets the user's home directory to read ~/.claude/skills/audit-workflow.md. This pattern exposes local file contents to the LLM's context, which could be used to harvest configuration data or other skill instructions stored on the host machine.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 18, 2026, 11:52 PM
Security Audit — agent-trust-hub — audit-perf