ai-coding-agents-settings-policy

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides guidance for processing repository-level instruction files like AGENTS.md, CLAUDE.md, and .goosehints, which are ingestion points for potentially untrusted collaborator data.
  • Ingestion points: Loads instructions from project-narrative files including AGENTS.md, CLAUDE.md, and .cursorrules.
  • Boundary markers: Recommends implementing "trust gates" for dangerous customization surfaces and "validating at the boundary."
  • Capability inventory: Policies govern high-risk surfaces including ToolSearch enablement, plugin surface activation, and execution of session hooks.
  • Sanitization: Advises for the targeted filtering of invalid permission rules and re-deriving runtime state after configuration changes to maintain security invariants.
  • [EXTERNAL_DOWNLOADS]: The skill references and fetches configuration guidelines from trusted organizations including Anthropic and OpenAI (e.g., code.claude.com, openai.com, and developers.openai.com).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — ai-coding-agents-settings-policy