hud
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONPERSISTENCEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes several
node -esnippets withinSKILL.mdto perform environment checks, verify file existence, and manage directory structures within the~/.claudedirectory.\n- [PERSISTENCE]: The skill modifiessettings.jsonto configure thestatusLineproperty, which triggers the execution of the HUD script every time the Claude Code environment starts. This is a legitimate mechanism for providing real-time status updates within the platform.\n- [DYNAMIC_EXECUTION]: A wrapper script (omc-hud.mjs) is generated by copying a local template file and is subsequently marked as executable to provide the HUD logic.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes dynamic data from the environment and configuration files.\n - Ingestion points: System environment variables and the
settings.jsonfile mentioned inSKILL.md.\n - Boundary markers: None present for display strings.\n
- Capability inventory: File writing (
cp,Edit tool), shell execution (node -e), and permission modification (chmod) found inSKILL.md.\n - Sanitization: Implements a
safeModethat sanitizes output by stripping ANSI codes and enforcing ASCII characters.
Audit Metadata