mot
Warn
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFEPRIVILEGE_ESCALATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill checks and utilizes the
DATABASE_URLenvironment variable to test database connectivity. Passing this variable directly to thepsqlcommand line exposes potential credentials to system process logs and shell history. - [PRIVILEGE_ESCALATION]: The skill includes a
--fixflag that executeschmod +xon shell scripts within the.claude/hooks/directory to modify execution permissions. - [DYNAMIC_EXECUTION]: The skill performs runtime execution of build scripts (
npm run build) and Python code viauv run pythonduring the audit and fix phases. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted configuration and metadata from project files to generate a health report.
- Ingestion points: Reads contents from
.claude/skills/SKILL.md,.claude/agents/*.md, and.claude/settings.json(SKILL.md, SKILL.md). - Boundary markers: Absent; the skill does not use delimiters or instructions to prevent the agent from obeying instructions embedded within the audited files.
- Capability inventory: Includes shell command execution, file permission modification, and database querying across multiple phases.
- Sanitization: Absent; extracted strings are processed using
grepandsedwithout escaping before being interpolated into the final report.
Audit Metadata