Skip to content

New: Nova rule for inject dynamic context in claude skills#6

Merged
fr0gger merged 4 commits intoNova-Hunting:mainfrom
marcopedrinazzi:dynamic-context-injection
Mar 19, 2026
Merged

New: Nova rule for inject dynamic context in claude skills#6
fr0gger merged 4 commits intoNova-Hunting:mainfrom
marcopedrinazzi:dynamic-context-injection

Conversation

@marcopedrinazzi
Copy link
Copy Markdown
Contributor

Hey Thomas, saw this pattern that i wasn't aware of: https://code.claude.com/docs/en/skills#inject-dynamic-context and I built a simple Nova rule to detect this. I think it'll be abused for sure to execute unwanted/malicious commands in skills

@fr0gger fr0gger merged commit 9249cf4 into Nova-Hunting:main Mar 19, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants