manager-setup

Pass

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: SAFEPERSISTENCEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PERSISTENCE]: The skill implements a persistent 'HARD wall' by registering a PreToolUse hook in the project's .claude/settings.local.json file. This hook remains active across sessions until explicitly uninstalled or purged.
  • [DYNAMIC_EXECUTION]: The skill frequently uses node -e (node evaluation) to execute complex logic for reading and writing project state and configuration files. This includes logic for merging JSON objects and performing atomic file operations.
  • [COMMAND_EXECUTION]: The skill executes shell commands (via the Bash tool) to copy script files, resolve plugin paths, and manage the execution of the project-local manager-state.mjs utility.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided tasks ($ARGUMENTS) and interpolates them with 'Manager' role instructions (references/full.md). While this lacks explicit sanitization markers, the risk is mitigated by the skill's primary purpose of restricting direct execution capabilities.
  • [EXTERNAL_DOWNLOADS]: The install and upgrade actions copy script files (hardmode-guard.mjs and manager-state.mjs) from the local plugin installation directory into the project's hidden .claude directory. These are internal vendor resources used for the skill's functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 8, 2026, 06:27 PM