skill-cleaner

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a bundled TypeScript utility script (scripts/skill-cleaner.ts) using the Node.js runtime. This script performs the file system traversal and analysis required to generate the audit report.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it processes external session log files to calculate skill usage statistics. While the script only extracts metadata and counts occurrences of skill names, it acts on data generated from previous interactions.
  • Ingestion points: Reads .jsonl and .log files from directories including ~/.pi/sessions, ~/.codex/sessions, and ~/.claude/projects.
  • Boundary markers: None; the script parses the full text of logs using regular expressions to find skill references.
  • Capability inventory: The script performs file reads and outputs a summary to the console; it does not perform network operations or file writes.
  • Sanitization: The script uses specific regex patterns to identify skill triggers (e.g., $skill-name) and does not directly render the raw contents of the logs in its output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — skill-cleaner