claude-code
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill documents the use of a CLI tool designed to perform shell commands, file modifications, and git operations. It provides implementation examples for running these commands via a terminal and managing interactive sessions using tmux.
- [INDIRECT_PROMPT_INJECTION]: The documented CLI tool possesses the capability to ingest external data, such as git diffs, pull request metadata, and content from web searches. This ingestion creates a potential surface for indirect prompt injection. The documentation addresses this by providing examples of security hooks that monitor tool inputs for malicious patterns. The ingestion points include git diffs, PR reviews, and piped inputs, while capabilities include shell execution and file system access. The instructions recommend reviewing prompts and using security hooks for sanitization.
- [EXTERNAL_DOWNLOADS]: The instructions include steps for installing the CLI tool and various Model Context Protocol (MCP) servers from public package registries. These resources are provided by a well-known service provider.
- [DYNAMIC_EXECUTION]: The skill describes how to define custom hooks and subagents that execute logic based on specific events. It includes a specific example of a security hook designed to identify and block recursive process spawning (fork bombs) within command strings to protect the execution environment.
Audit Metadata