klh-agents-md
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use
findandlsto locateSKILL.mdfiles in the.claude/skillsandplugins/directories. It also specifies the use ofln -sto create a symbolic link between AGENTS.md and CLAUDE.md. These are standard file system operations used for project organization and discovery. - [INDIRECT_PROMPT_INJECTION]: The agent is directed to read the content of discovered local
SKILL.mdfiles to understand how to reference them in project documentation. This creates an attack surface where malicious content in those local files could influence the agent's output. - Ingestion points: The agent reads local
SKILL.mdfiles located in.claude/skills/andplugins/*/skills/*/directories. - Boundary markers: There are no explicit instructions or delimiters provided to the agent to treat the content of these files as untrusted or to ignore embedded instructions.
- Capability inventory: The skill utilizes
find,ls,ln, and file-reading capabilities. - Sanitization: No sanitization or validation of the content found in the local
SKILL.mdfiles is specified.
Audit Metadata