claude-md-improver

Warn

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill metadata claims the author is 'claude-plugins-official', which contradicts the provided author information 'JNZader-Vault'. This use of 'official' is deceptive and could mislead users regarding the skill's provenance.
  • [PROMPT_INJECTION]: The skill exhibits an Indirect Prompt Injection surface because it reads and processes user-controlled data to influence its audit reports and file update proposals.
  • Ingestion points: Uses the Read and Glob tools to fetch content from files named CLAUDE.md, .claude.md, and .claude.local.md, as well as global configuration at ~/.claude/CLAUDE.md.
  • Boundary markers: There are no instructions for the agent to use delimiters or ignore embedded instructions when reading these files.
  • Capability inventory: The skill has access to the Bash and Edit tools, which could be abused if malicious instructions in the audited files are followed.
  • Sanitization: No sanitization or schema validation is performed on the ingested content.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute shell commands for discovery purposes, specifically using 'find' to locate configuration files within the project directory.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 19, 2026, 09:41 PM
Security Audit — agent-trust-hub — claude-md-improver