ai-coding-agents-settings-policy
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides guidance for processing repository-level instruction files like
AGENTS.md,CLAUDE.md, and.goosehints, which are ingestion points for potentially untrusted collaborator data. - Ingestion points: Loads instructions from project-narrative files including
AGENTS.md,CLAUDE.md, and.cursorrules. - Boundary markers: Recommends implementing "trust gates" for dangerous customization surfaces and "validating at the boundary."
- Capability inventory: Policies govern high-risk surfaces including
ToolSearchenablement, plugin surface activation, and execution of session hooks. - Sanitization: Advises for the targeted filtering of invalid permission rules and re-deriving runtime state after configuration changes to maintain security invariants.
- [EXTERNAL_DOWNLOADS]: The skill references and fetches configuration guidelines from trusted organizations including Anthropic and OpenAI (e.g.,
code.claude.com,openai.com, anddevelopers.openai.com).
Audit Metadata