workflow-optimization
Warn
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill generates and executes multiple bash scripts in the
~/.claude/hooks/directory to automate developer tasks such as formatting, type checking, and reflection reminders. - [REMOTE_CODE_EXECUTION]: The skill employs dynamic script generation and execution by creating local
.shfiles and configuring the agent's~/.claude/settings.jsonto run these scripts automatically viaSessionStart,PostToolUse, andSessionEndhooks. - [PROMPT_INJECTION]: An indirect prompt injection surface is created by the
load-mistakes.shhook, which reads content from.claude/mistakes.mdand injects it directly into the agent's context as asystemMessageat the start of every session without sanitization. - Ingestion points:
.claude/mistakes.md(read by~/.claude/hooks/load-mistakes.sh). - Boundary markers: Absent; the extracted lesson content is interpolated directly into a JSON
systemMessageblock. - Capability inventory: The agent has full access to the shell (
Bash), file system (Read,Edit), and version control (git). - Sanitization: Content is escaped for JSON structure using
jq, but no validation or filtering is performed on the actual text to prevent embedded instructions from influencing the agent.
Audit Metadata