agents-md
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process instructions from files like
AGENTS.mdandCLAUDE.mdwithin a repository workspace. This represents a significant surface for indirect prompt injection. - Ingestion points: Instruction files discovered via
findandls(e.g.,AGENTS.md,CLAUDE.md,CLAUDE.local.md) and refactored using the instructions inSKILL.mdandreferences/refactor-workflow.md. - Boundary markers: The skill does not define specific delimiters or instructions to ignore malicious embedded content when auditing or refactoring these files.
- Capability inventory: The skill utilizes file discovery (
find,ls), skill management (npx skills add), command execution (claude -p,codex exec), and file modification capabilities. - Sanitization: No sanitization or filtering of external instruction content is specified before processing or applying edits.
- [DATA_EXFILTRATION]: The skill accesses user-level configuration and instruction files stored in hidden home directory paths, specifically
~/.claude/CLAUDE.md,~/.claude/settings.json, and~/.codex/AGENTS.md. These files can contain sensitive project-specific information or user preferences. - [COMMAND_EXECUTION]: The skill instructions mandate 'smoke-running' core repository commands (such as
dev,test,build, andlint) extracted from the repository's manifest. It also executes verification probes throughclaude -pandcodex exec. These actions risk the execution of arbitrary malicious code if the project workspace is compromised. - [EXTERNAL_DOWNLOADS]: The skill references the installation of external agent skills using the
npx skills add <owner>/<repo>command, which downloads and installs code from external repositories into the user's environment.
Audit Metadata