wrap-up-session
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is designed to automatically execute arbitrary shell commands parsed from the project's
CLAUDE.mdfile. Step 0 and Step 4 instruct the agent to find and run 'sync commands, restart commands, or deploy scripts' documented under specific headings. If a project file is modified by an untrusted party (e.g., via a malicious Pull Request), this behavior could lead to the execution of unintended commands. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface where instructions embedded in project data are treated as commands to be executed.
- Ingestion points: The
CLAUDE.mdfile is read and its contents are parsed for executable instructions in Step 0 and Step 4. - Boundary markers: None. The skill does not implement delimiters or 'ignore' instructions for the content read from the file.
- Capability inventory: The skill has the capability to execute shell commands, perform git operations (commit/push), and modify files in the local repository and the
~/.claude/directory. - Sanitization: There is no evidence of validation or sanitization of the commands extracted from the documentation before execution.
- [COMMAND_EXECUTION]: The skill references and encourages the execution of a specific local script at
~/.claude/scripts/memory-audit.js. This assumes the script's integrity and presence in the user's home directory.
Audit Metadata