context-engineering
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPERSISTENCE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill promotes a strategy of reading from external files like
NOTES.md,CLAUDE.md, and.claude/critical-context.mdto maintain session state. This creates a surface where malicious instructions embedded in these files (e.g., via a compromised repository or pull request) could influence the agent's behavior. - Ingestion points:
NOTES.md,CLAUDE.md,.claude/memory/, and.claude/critical-context.mdas described inSKILL.md. - Boundary markers: The skill does not suggest the use of delimiters or instructions to ignore embedded commands within these persistent files.
- Capability inventory: The skill references the use of
grep,Glob,cat, and the creation of subagents to process information. - Sanitization: There is no mention of sanitizing or validating the content of external files before injecting them into the primary context.
- [COMMAND_EXECUTION]: The skill includes an example configuration for a
PostCompacthook that executes the shell commandcat .claude/critical-context.md. While used for context management, this involves shell-level execution of file reads. - [PERSISTENCE]: The skill describes methods to ensure information survives session boundaries and compaction events using durable storage such as
.claude/memory/andCLAUDE.md. This represents a persistence mechanism for agent instructions, allowing state to remain active across different tasks.
Audit Metadata