ai-coding-agents-permissions
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is primarily documentation and architectural guidance intended to assist developers in building secure permission layers. It does not contain executable code or scripts that perform malicious operations.
- [EXTERNAL_DOWNLOADS]: The skill references official documentation and public source code repositories for reference purposes. These connections are intended for information gathering on best practices and do not involve downloading or executing untrusted payloads.
- [INDIRECT_PROMPT_INJECTION]: The skill identifies and documents the attack surface for indirect prompt injection within agent runtimes. It provides mitigation strategies, such as using classifiers to strip tool results of injected instructions (as seen in the description of Claude Code's auto mode) and linting rules for dangerous breadth (referenced in the Host Rules and Failure Modes sections of SKILL.md). Evidence chain: Ingestion points include tool arguments and results; boundary markers include the mention of model-classifier approval systems; capability inventory includes file system and shell execution controls; sanitization is addressed through rule linting and path-anchoring guidelines.
Audit Metadata