skill-developer
Pass
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The documentation provides instructions to execute local shell commands and scripts using 'npx tsx', 'chmod +x', and 'npm install' for testing and initializing the hook system within the developer's environment.\n- [DATA_EXFILTRATION]: The skill utilizes local environment variables and session state files stored in '.claude/hooks/state/' to manage configuration and track skill activation history, which is consistent with the described system architecture.\n- [PROMPT_INJECTION]: The guide describes a mechanism for injecting automated context into the agent's prompt via the 'UserPromptSubmit' hook. This is presented as a feature for skill activation awareness and includes clear formatting boundaries for the injected content.
Audit Metadata