workflow-optimization

Warn

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill generates and executes multiple bash scripts in the ~/.claude/hooks/ directory to automate developer tasks such as formatting, type checking, and reflection reminders.
  • [REMOTE_CODE_EXECUTION]: The skill employs dynamic script generation and execution by creating local .sh files and configuring the agent's ~/.claude/settings.json to run these scripts automatically via SessionStart, PostToolUse, and SessionEnd hooks.
  • [PROMPT_INJECTION]: An indirect prompt injection surface is created by the load-mistakes.sh hook, which reads content from .claude/mistakes.md and injects it directly into the agent's context as a systemMessage at the start of every session without sanitization.
  • Ingestion points: .claude/mistakes.md (read by ~/.claude/hooks/load-mistakes.sh).
  • Boundary markers: Absent; the extracted lesson content is interpolated directly into a JSON systemMessage block.
  • Capability inventory: The agent has full access to the shell (Bash), file system (Read, Edit), and version control (git).
  • Sanitization: Content is escaped for JSON structure using jq, but no validation or filtering is performed on the actual text to prevent embedded instructions from influencing the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 16, 2026, 11:34 AM