Vague Triggers
High
- Confidence
- 97% confidence
- Finding
- The skill is configured to auto-run on every user message without explicit invocation, which creates a broad and persistent attack surface. Because it reads and injects CLAUDE.md content from the workspace into system context, an attacker-controlled repository can influence model behavior on unrelated prompts and turn ordinary conversations into prompt-injection opportunities.
