therapist-documentation

Warn

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill directs the agent to read sensitive configuration and environment definitions to understand the system architecture. This creates an exposure risk for credentials or secrets stored in these files. Evidence: SKILL.md, Phase 1: 'Read configuration files, dependency manifests, and environment definitions.'
  • [PROMPT_INJECTION]: The skill analyzes local codebase content and takes user arguments without employing boundary markers or sanitization. This allows for indirect prompt injection if the audited files contain malicious instructions. Ingestion points: User-provided arguments and local system files. Boundary markers: None identified. Capability inventory: Extensive file reading and local logging. Sanitization: No evidence of data cleaning before processing.
  • [COMMAND_EXECUTION]: The skill includes instructions to write execution metadata to a hidden local directory ('~/.claude/projects/') for telemetry purposes. Evidence: SKILL.md, 'SELF-EVOLUTION TELEMETRY' section.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 16, 2026, 01:00 AM
Security Audit — agent-trust-hub — therapist-documentation