context-loader

Pass

Audited by Gen Agent Trust Hub on Feb 18, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • Indirect Prompt Injection (LOW): The skill is designed to ingest and follow instructions from files within the .claude/ directory.
  • Ingestion points: .claude/rules/.md, .claude/docs/DESIGN.md, .claude/docs/libraries/.md.
  • Boundary markers: Absent. The skill does not instruct the agent to distinguish between its own system prompt and the loaded data or to treat the external content as potentially untrusted.
  • Capability inventory: The skill prepares the agent for general task execution, which typically includes file system access and tool usage in the context of coding.
  • Sanitization: Absent. Content from the files is used directly to guide the agent's reasoning, logic, and code generation processes.
  • Prompt Injection (LOW): The description includes a directive ('ALWAYS activate this skill at the start of every task') intended to ensure the skill's logic is prioritized and persistent across all agent sessions, which is a common prompt injection pattern to override standard behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 18, 2026, 06:43 AM