start-session
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from project files to determine which commands to execute and which directories to access, creating a vulnerability surface where a malicious project file can control agent behavior.
- Ingestion points: The skill reads
CLAUDE.mdto find synchronization commands (Step 0/1) and filesystem paths for related repositories or agent inboxes (Step 5b). - Boundary markers: None present. The agent is not instructed to treat these inputs as data or to ignore embedded instructions; instead, it is explicitly told to execute the findings.
- Capability inventory: The skill has the capability to execute shell commands, perform network operations via
git pull, and navigate the filesystem based on the ingested data. - Sanitization: No sanitization or validation logic is present to verify the safety of the commands or paths extracted from the project files.
- [COMMAND_EXECUTION]: Step 1 of the skill instructions mandates the execution of synchronization commands (e.g.,
rsync,git pull) found withinCLAUDE.md. This pattern of executing commands defined in a data file is inherently risky if the repository content is not fully trusted by the user.
Audit Metadata