hud

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONPERSISTENCEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes several node -e snippets within SKILL.md to perform environment checks, verify file existence, and manage directory structures within the ~/.claude directory.\n- [PERSISTENCE]: The skill modifies settings.json to configure the statusLine property, which triggers the execution of the HUD script every time the Claude Code environment starts. This is a legitimate mechanism for providing real-time status updates within the platform.\n- [DYNAMIC_EXECUTION]: A wrapper script (omc-hud.mjs) is generated by copying a local template file and is subsequently marked as executable to provide the HUD logic.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes dynamic data from the environment and configuration files.\n
  • Ingestion points: System environment variables and the settings.json file mentioned in SKILL.md.\n
  • Boundary markers: None present for display strings.\n
  • Capability inventory: File writing (cp, Edit tool), shell execution (node -e), and permission modification (chmod) found in SKILL.md.\n
  • Sanitization: Implements a safeMode that sanitizes output by stripping ANSI codes and enforcing ASCII characters.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:35 PM
Security Audit — agent-trust-hub — hud