conventions-claude

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a documentation overlay for Claude Code conventions, defining standards for plugin manifests, agent frontmatter, and hook event schemas.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill documents the !command syntax used in Claude Code for dynamic context injection. As this is part of a documentation guide and does not include malicious commands meant for execution during the loading of this specific skill, it is considered safe practice.
  • [EXTERNAL_DOWNLOADS]: The skill references authoritative documentation at code.claude.com. These are links to well-known service documentation and do not constitute a security risk.
  • [COMMAND_EXECUTION]: The skill describes how commands, hooks, and LSP servers are configured in the Claude Code environment. It does not contain any immediate command execution payloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:57 PM
Security Audit — agent-trust-hub — conventions-claude