rules-capture

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest untrusted user input and transform it into rules stored in persistent configuration files like CLAUDE.md and AGENTS.md. This creates a vulnerability surface where adversarial user input could be 'captured' and promoted to permanent system instructions. The risk is mitigated by the skill's requirement for explicit user confirmation before promotion and its automated redaction of sensitive data.
  • [PERSISTENCE]: The primary function of the skill is to modify agent configuration files that persist across sessions. While this behavior is characteristic of persistence mechanisms, it is the documented and intended purpose of the tool for managing local agent behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:10 AM
Security Audit — agent-trust-hub — rules-capture