prune
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill evaluates instructions and metadata of other skills, which introduces a theoretical surface for indirect prompt injection. 1. Ingestion points: SKILL.md frontmatter and CAPABILITIES_SUMMARY from directories in ~/.claude/skills/. 2. Boundary markers: Absent for scanned content. 3. Capability inventory: Read-only file system access for inventory and activity analysis; no network or shell execution capabilities. 4. Sanitization: No explicit content sanitization is described for the audited data.
- [SAFE]: The skill's operations are confined to its stated purpose of skill gardening. It lacks the ability to execute code or exfiltrate data, and its architecture enforces human-in-the-loop for all destructive actions.
Audit Metadata