claude-project-setup

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill is purely instructional and text-based. It provides a framework for generating project documentation to orient AI agents.
  • [NO_CODE]: The skill does not include any scripts, executable commands, or tool invocations. It operates solely as a prompt template for the AI agent to interact with the user.
  • [DATA_EXPOSURE_&_EXFILTRATION]: No evidence of sensitive file access, hardcoded credentials, or network exfiltration attempts. The skill only asks for project-related information to build a documentation file.
  • [REMOTE_CODE_EXECUTION]: There are no patterns of remote code execution, package installations, or external script downloads.
  • [OBFUSCATION]: The content is written in clear, plain Markdown with no hidden characters, encoded strings, or obfuscated URLs.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests user input about a project, it does not possess capabilities (like file writes or shell execution) that would make it vulnerable to exploitation. The risk is limited to the generated text content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 05:56 PM
Security Audit — agent-trust-hub — claude-project-setup