cc-stack-sync
Pass
Audited by Gen Agent Trust Hub on Aug 13, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill ingests untrusted data from repository files such as CLAUDE.md and README.md during fingerprinting and merging operations. However, it implements boundary markers like the
<!-- plugin:cc-setup managed -->comment and uses a structured section-merge protocol that preserves user-curated sections. The capability inventory includes writing to the.claude/directory and calling MCP tools for configuration recommendations. Sanitization is achieved through user confirmation requirements for destructive drift repairs.- [EXTERNAL_DOWNLOADS]: Skill and LSP management. The skill detects outdated versions of agent skills in the.claude/skills/directory and missing LSP servers, offering to download or install replacements. These actions are performed within the intended scope of repository maintenance.- [COMMAND_EXECUTION]: Assisted tool setup. The skill provides installation commands for Language Server Protocol (LSP) servers after detecting them in the repository stack, requiring user interaction to execute.
Audit Metadata