permission-tuner
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
catandgrepto read local configuration files (.claude/settings.jsonand~/.claude/settings.json) to analyze current permission states. This is a standard operation for a configuration utility and is limited to reading the agent's own settings. - [INDIRECT_PROMPT_INJECTION]: The skill ingests 'session data' to identify frequently used tools. While processing external data poses a theoretical risk, the skill includes several safety layers:
- Sanitization: It explicitly categories risky commands (destructive actions, external API calls) for the deny list.
- Boundary Markers: The workflow requires presenting rules for user approval before applying changes.
- Capability Inventory: The skill itself only reads configuration and generates text recommendations; it does not automatically write to the configuration files.
Audit Metadata