skills/xiaobei930/cc-best/learning/Gen Agent Trust Hub

learning

Pass

Audited by Gen Agent Trust Hub on Mar 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONNO_CODE
Full Analysis
  • [COMMAND_EXECUTION]: The skill documentation and metadata specify the use of the Bash tool to execute local scripts (evaluate-session.js and observe-patterns.js) for session evaluation and pattern monitoring. These scripts are treated as vendor-owned resources for the author xiaobei930.\n- [PROMPT_INJECTION]: The skill facilitates an indirect prompt injection surface (Category 8) by extracting patterns from untrusted session data and persisting them into core instruction files like CLAUDE.md and rules/. Evidence Chain: (1) Ingestion points: Session logs and observations.jsonl tool-use records. (2) Boundary markers: Not present in templates. (3) Capability inventory: Write, Edit, and Bash used to update system-level instructions. (4) Sanitization: Relies on auto_approve: false configuration for manual review, lacking automated sanitization or filtering.\n- [NO_CODE]: The functional logic for the skill's automated hooks resides in external scripts within the scripts/node/hooks/ directory, which were not provided for analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 6, 2026, 06:01 AM