TIL Claude Code allows Skills to run commands to inject content. This behavior is enabled by default, runs silently, & doesn't require user approval.
There are some guardrails, but I was able to inject a .env file with no complaints! ๐คฏ
drskill has been updated to guard against this avenue of exploits: