install-skill-tracker
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill captures and stores user prompts, skill names, and session IDs in local JSONL files located at
.claude/activity-logs/. This behavior is the primary function of the skill and is performed locally without network transmission. The installation process proactively adds this directory to.gitignoreto prevent accidental exposure via version control.\n- [COMMAND_EXECUTION]: The skill utilizes Bash scripts (track-prompts.sh,track-skill-start.sh,track-skill-end.sh) and a Python script (analyze-skills.py) to handle data logging and report generation. These scripts are executed through the standard Claude Code hook system.\n- [PERSISTENCE]: The skill configures project-level hooks by modifying.claude/settings.json, which allows the tracking system to persist and run automatically during subsequent Claude Code sessions in the project.\n- [INDIRECT_PROMPT_INJECTION]: The analysis script processes user prompts stored in the log files. It mitigates potential display issues by truncating long strings and escaping markdown table characters, which is a best practice when handling stored user input for reporting.
Audit Metadata