mot

Warn

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFEPRIVILEGE_ESCALATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill checks and utilizes the DATABASE_URL environment variable to test database connectivity. Passing this variable directly to the psql command line exposes potential credentials to system process logs and shell history.
  • [PRIVILEGE_ESCALATION]: The skill includes a --fix flag that executes chmod +x on shell scripts within the .claude/hooks/ directory to modify execution permissions.
  • [DYNAMIC_EXECUTION]: The skill performs runtime execution of build scripts (npm run build) and Python code via uv run python during the audit and fix phases.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted configuration and metadata from project files to generate a health report.
  • Ingestion points: Reads contents from .claude/skills/SKILL.md, .claude/agents/*.md, and .claude/settings.json (SKILL.md, SKILL.md).
  • Boundary markers: Absent; the skill does not use delimiters or instructions to prevent the agent from obeying instructions embedded within the audited files.
  • Capability inventory: Includes shell command execution, file permission modification, and database querying across multiple phases.
  • Sanitization: Absent; extracted strings are processed using grep and sed without escaping before being interpolated into the final report.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 18, 2026, 05:11 PM
Security Audit — agent-trust-hub — mot