claude-md-refresh
Pass
Audited by Gen Agent Trust Hub on Apr 8, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill facilitates Indirect Prompt Injection by parsing and merging untrusted content from CLAUDE.md and templates without sanitization or boundary markers.
- Ingestion points: Reads CLAUDE.md and template files.
- Boundary markers: Absent; uses header-based splitting to process content.
- Capability inventory: File system read and write access to the project's CLAUDE.md file.
- Sanitization: No validation or filtering of the merged content is performed before updating the configuration.
Audit Metadata