claude-peers-bible
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
- [NO_CODE]: The provided skill is documentation-only, consisting of a markdown file with no executable scripts, configuration files, or binaries.
- [PROMPT_INJECTION]: The skill documents a communication model that ingests data from other agent instances, creating a surface for potential indirect prompt injection.
- Ingestion points: Peer messages received via the
check_messagestool or theclaude-peerschannel (SKILL.md). - Boundary markers: The documentation does not specify the use of delimiters or boundary markers to isolate instructions embedded in peer messages.
- Capability inventory: The coordination workflows involve agents performing file writes, merging code, and executing build pipelines based on peer input.
- Sanitization: No methods for validating or sanitizing message content are discussed in the guide.
Audit Metadata