configure-notifications
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill supports the configuration of
custom_cli_command, which enables the execution of arbitrary shell commands based on user-provided templates.\n- [INDIRECT_PROMPT_INJECTION]: The skill interpolates dynamic project and session metadata into shell commands (such asclawdbot agent), creating a risk of command injection if the metadata contains malicious characters.\n - Ingestion points: Placeholders like
{{projectName}},{{question}},{{reason}}, and{{instruction}}are used in command templates withinSKILL.md.\n - Boundary markers: There are no boundary markers or instructions provided to the agent to distinguish between data and instructions during interpolation.\n
- Capability inventory: The skill uses
jq,mv, and theclawdbotCLI tool for shell command execution.\n - Sanitization: No escaping or validation of the interpolated data is performed within the skill code itself.
Audit Metadata