scaffold-claude
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by reading local project files. Ingestion points: Workflow Step 1 in
SKILL.mdreads local files likepackage.jsonandREADME.md. Boundary markers: The skill does not use technical boundary markers for ingested file content. Capability inventory: Workflow Step 3 inSKILL.mdallows writing to the local file system (docs/scratchpad/CLAUDE.md). Sanitization: The risk is mitigated by an interview process that acts as a human-in-the-loop review of the content before any file is written.
Audit Metadata