claude-settings-audit
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill performs project reconnaissance using
ls,find, andcatto discover the tech stack and existing settings. It also recommends providing the agent with broad access to thegh apitool. - [EXTERNAL_DOWNLOADS]: The skill suggests including the
@linear/mcp-serverpackage in the project's Model Context Protocol configuration. - [INDIRECT_PROMPT_INJECTION]: The skill analyzes external dependency and configuration files which are managed by the project owners and could contain instructions targeting the auditor.
- Ingestion points:
package.json,pyproject.toml,Gemfile,Cargo.toml, and other project metadata files. - Boundary markers: None identified.
- Capability inventory: File discovery and read operations (
ls,find,cat). - Sanitization: None identified.
Audit Metadata