manager-setup
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFEPERSISTENCEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PERSISTENCE]: The skill implements a persistent 'HARD wall' by registering a
PreToolUsehook in the project's.claude/settings.local.jsonfile. This hook remains active across sessions until explicitly uninstalled or purged. - [DYNAMIC_EXECUTION]: The skill frequently uses
node -e(node evaluation) to execute complex logic for reading and writing project state and configuration files. This includes logic for merging JSON objects and performing atomic file operations. - [COMMAND_EXECUTION]: The skill executes shell commands (via the Bash tool) to copy script files, resolve plugin paths, and manage the execution of the project-local
manager-state.mjsutility. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided tasks (
$ARGUMENTS) and interpolates them with 'Manager' role instructions (references/full.md). While this lacks explicit sanitization markers, the risk is mitigated by the skill's primary purpose of restricting direct execution capabilities. - [EXTERNAL_DOWNLOADS]: The
installandupgradeactions copy script files (hardmode-guard.mjsandmanager-state.mjs) from the local plugin installation directory into the project's hidden.claudedirectory. These are internal vendor resources used for the skill's functionality.
Audit Metadata