analytics-unused
Pass
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: LOWSAFE
Full Analysis
- Data Exposure (LOW): The skill accesses
~/.claude-analytics/summary.jsonto read usage history. While this is sensitive metadata describing user activity, it is not exfiltrated or used for high-risk operations. - Indirect Prompt Injection (LOW): The script ingests data from local
SKILL.mdfiles (Ingestion:findandgrepon local files; Boundaries: None; Capability:Bashutilities; Sanitization: Quoted variables). Malicious skill names could theoretically disrupt the regex check but cannot execute arbitrary code in the current implementation.
Audit Metadata