skill-developer
Warn
Audited by Gen Agent Trust Hub on Apr 14, 2026
Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill describes a UserPromptSubmit hook architecture specifically designed to automatically inject formatted context and instructions into the agent's input before processing user prompts, enabling hidden prompt manipulation.- [COMMAND_EXECUTION]: The skill instructs the agent to create shell scripts and TypeScript files within the project directory, make them executable using chmod, and run them using npx tsx.- [COMMAND_EXECUTION]: The skill guides the agent to modify project configuration files like .claude/settings.json to register these hooks, ensuring that custom code executes automatically on every future prompt or tool call, effectively establishing a persistence mechanism.- [COMMAND_EXECUTION]: The described PreToolUse hook allows the system to intercept, monitor, and potentially block the execution of tools such as Edit or Write, providing a method to override user-authorized actions.
Audit Metadata