sigil
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the repository being analyzed, including manifest files, source code, and AI-specific rule files (e.g.,
CLAUDE.md,.cursorrules). This data is used to generate executable skill instructions and configurations, potentially allowing a malicious repository to manipulate the output. - Ingestion points: Project manifest files (
package.json,go.mod, etc.), source code directories, and various AI rule files as defined in thereference/cross-tool-rules-landscape.mdfile. - Boundary markers: The skill employs a "path + selective excerpt strategy" during scanning to minimize ingestion of unnecessary data.
- Capability inventory: The skill utilizes
Bash,Read,Glob, andGreptools and has the capability to write to project-specific skill directories (.claude/skills/). - Sanitization: Instructions explicitly warn against including XML angle brackets in YAML frontmatter to prevent prompt-injection hazards.
- [DYNAMIC_CONTEXT_INJECTION]: The skill documents and supports the generation of skills utilizing the
!command`` syntax for dynamic context injection. This feature allows shell command output to be injected into the agent's prompt at load time. The skill provides benign examples (e.g.,git branch) and advises using only trusted commands. - [COMMAND_EXECUTION]: The skill performs project analysis by executing shell commands (e.g.,
git,cat,jq) via theBashtool to detect tech stacks, dependencies, and current project state.
Audit Metadata