install-skill-tracker

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill captures and stores user prompts, skill names, and session IDs in local JSONL files located at .claude/activity-logs/. This behavior is the primary function of the skill and is performed locally without network transmission. The installation process proactively adds this directory to .gitignore to prevent accidental exposure via version control.\n- [COMMAND_EXECUTION]: The skill utilizes Bash scripts (track-prompts.sh, track-skill-start.sh, track-skill-end.sh) and a Python script (analyze-skills.py) to handle data logging and report generation. These scripts are executed through the standard Claude Code hook system.\n- [PERSISTENCE]: The skill configures project-level hooks by modifying .claude/settings.json, which allows the tracking system to persist and run automatically during subsequent Claude Code sessions in the project.\n- [INDIRECT_PROMPT_INJECTION]: The analysis script processes user prompts stored in the log files. It mitigates potential display issues by truncating long strings and escaping markdown table characters, which is a best practice when handling stored user input for reporting.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 06:32 PM