claude-settings-audit

Pass

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The agent uses ls, find, and cat to identify project files and existing configurations. These are read-only operations for environmental discovery.
  • [EXTERNAL_DOWNLOADS]: Installation instructions reference npx to download the skill from the author's GitHub repository. This is a recognized installation method for the toolset.
  • [PROMPT_INJECTION]: The skill ingests untrusted data by reading repository manifests which presents an indirect prompt injection surface.
  • Ingestion points: Reads repository dependency and configuration files using cat.
  • Boundary markers: None.
  • Capability inventory: Read-only discovery commands and recommendations for CLI tool access including gh api:*.
  • Sanitization: None.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 16, 2026, 01:13 PM
Security Audit — agent-trust-hub — claude-settings-audit