claude-settings-audit

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs project reconnaissance using ls, find, and cat to discover the tech stack and existing settings. It also recommends providing the agent with broad access to the gh api tool.
  • [EXTERNAL_DOWNLOADS]: The skill suggests including the @linear/mcp-server package in the project's Model Context Protocol configuration.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes external dependency and configuration files which are managed by the project owners and could contain instructions targeting the auditor.
  • Ingestion points: package.json, pyproject.toml, Gemfile, Cargo.toml, and other project metadata files.
  • Boundary markers: None identified.
  • Capability inventory: File discovery and read operations (ls, find, cat).
  • Sanitization: None identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 08:43 PM
Security Audit — agent-trust-hub — claude-settings-audit