start-session

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from project files to determine which commands to execute and which directories to access, creating a vulnerability surface where a malicious project file can control agent behavior.
  • Ingestion points: The skill reads CLAUDE.md to find synchronization commands (Step 0/1) and filesystem paths for related repositories or agent inboxes (Step 5b).
  • Boundary markers: None present. The agent is not instructed to treat these inputs as data or to ignore embedded instructions; instead, it is explicitly told to execute the findings.
  • Capability inventory: The skill has the capability to execute shell commands, perform network operations via git pull, and navigate the filesystem based on the ingested data.
  • Sanitization: No sanitization or validation logic is present to verify the safety of the commands or paths extracted from the project files.
  • [COMMAND_EXECUTION]: Step 1 of the skill instructions mandates the execution of synchronization commands (e.g., rsync, git pull) found within CLAUDE.md. This pattern of executing commands defined in a data file is inherently risky if the repository content is not fully trusted by the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:09 PM