Was reminded about this again today and it still blows my mind.
TIL Claude Code allows Skills to run commands to inject content. This behavior is enabled by default, runs silently, & doesn't require user approval.
There are some guardrails, but I was able to inject a .env file with no complaints! 🤯
drskill has been updated to guard against this avenue of exploits:
顯示更多