skills/petekp/claude-code-setup/plain/Gen Agent Trust Hub

plain

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes untrusted content from pasted text or files. Ingestion points: Arguments provided to the /plain command or informal triggers like 'explain that more simply'. Boundary markers: None present; the skill does not use delimiters or specific instructions to isolate and ignore commands within user-provided content. Capability inventory: The skill explicitly instructs the agent to read files when a path is provided. Sanitization: No sanitization, escaping, or validation of the input text is performed.
  • [DATA_EXFILTRATION]: The skill formalizes a request for the agent to read local files via user-supplied paths. This functionality could lead to the exposure of sensitive data if the agent's file access tools are not properly restricted to safe directories, as the agent is instructed to 'Read the file first if given a path' and then output its restated contents.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 03:45 PM
Security Audit — agent-trust-hub — plain