wrap-up-session

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed to automatically execute arbitrary shell commands parsed from the project's CLAUDE.md file. Step 0 and Step 4 instruct the agent to find and run 'sync commands, restart commands, or deploy scripts' documented under specific headings. If a project file is modified by an untrusted party (e.g., via a malicious Pull Request), this behavior could lead to the execution of unintended commands.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface where instructions embedded in project data are treated as commands to be executed.
  • Ingestion points: The CLAUDE.md file is read and its contents are parsed for executable instructions in Step 0 and Step 4.
  • Boundary markers: None. The skill does not implement delimiters or 'ignore' instructions for the content read from the file.
  • Capability inventory: The skill has the capability to execute shell commands, perform git operations (commit/push), and modify files in the local repository and the ~/.claude/ directory.
  • Sanitization: There is no evidence of validation or sanitization of the commands extracted from the documentation before execution.
  • [COMMAND_EXECUTION]: The skill references and encourages the execution of a specific local script at ~/.claude/scripts/memory-audit.js. This assumes the script's integrity and presence in the user's home directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:09 PM