claude-expert

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: A static analysis alert for instruction override patterns was identified in the security documentation. Analysis confirms this is a false positive; the file discusses prompt injection as a threat model for event-driven integrations and provides mitigation strategies for developers. The skill also provides legitimate guidance on using emphasis keywords like "IMPORTANT" to improve instruction following.
  • [COMMAND_EXECUTION]: The documentation describes the functionality of tools like Claude Code and the Agent SDK, which include capabilities for executing shell commands. It includes robust security advice, discussing the trade-offs of autonomous execution flags and providing code examples for defensive "hooks" that block access to sensitive system paths or destructive commands.
  • [EXTERNAL_DOWNLOADS]: The skill provides official installation instructions for various SDKs and CLI tools using standard package managers (npm, pip, Homebrew) and references official release assets from the "anthropics" GitHub organization.
  • [SAFE]: No evidence of obfuscation, unauthorized data exfiltration, or malicious persistence was found. The skill serves as an educational and operational guide for building and managing Claude-based agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 04:00 AM
Security Audit — agent-trust-hub — claude-expert