permission-tuner

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses cat and grep to read local configuration files (.claude/settings.json and ~/.claude/settings.json) to analyze current permission states. This is a standard operation for a configuration utility and is limited to reading the agent's own settings.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests 'session data' to identify frequently used tools. While processing external data poses a theoretical risk, the skill includes several safety layers:
  • Sanitization: It explicitly categories risky commands (destructive actions, external API calls) for the deny list.
  • Boundary Markers: The workflow requires presenting rules for user approval before applying changes.
  • Capability Inventory: The skill itself only reads configuration and generates text recommendations; it does not automatically write to the configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 05:34 AM
Security Audit — agent-trust-hub — permission-tuner