claude-project-setup
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill is purely instructional and text-based. It provides a framework for generating project documentation to orient AI agents.
- [NO_CODE]: The skill does not include any scripts, executable commands, or tool invocations. It operates solely as a prompt template for the AI agent to interact with the user.
- [DATA_EXPOSURE_&_EXFILTRATION]: No evidence of sensitive file access, hardcoded credentials, or network exfiltration attempts. The skill only asks for project-related information to build a documentation file.
- [REMOTE_CODE_EXECUTION]: There are no patterns of remote code execution, package installations, or external script downloads.
- [OBFUSCATION]: The content is written in clear, plain Markdown with no hidden characters, encoded strings, or obfuscated URLs.
- [INDIRECT_PROMPT_INJECTION]: While the skill ingests user input about a project, it does not possess capabilities (like file writes or shell execution) that would make it vulnerable to exploitation. The risk is limited to the generated text content.
Audit Metadata