klh-agents-md

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use find and ls to locate SKILL.md files in the .claude/skills and plugins/ directories. It also specifies the use of ln -s to create a symbolic link between AGENTS.md and CLAUDE.md. These are standard file system operations used for project organization and discovery.
  • [INDIRECT_PROMPT_INJECTION]: The agent is directed to read the content of discovered local SKILL.md files to understand how to reference them in project documentation. This creates an attack surface where malicious content in those local files could influence the agent's output.
  • Ingestion points: The agent reads local SKILL.md files located in .claude/skills/ and plugins/*/skills/*/ directories.
  • Boundary markers: There are no explicit instructions or delimiters provided to the agent to treat the content of these files as untrusted or to ignore embedded instructions.
  • Capability inventory: The skill utilizes find, ls, ln, and file-reading capabilities.
  • Sanitization: No sanitization or validation of the content found in the local SKILL.md files is specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 10:41 AM
Security Audit — agent-trust-hub — klh-agents-md