underwriting-analysis

Warn

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted external data (project configuration files, database schemas, and rating algorithms) and interpolates them into its analytical process without boundary markers or sanitization.
  • Ingestion points: $ARGUMENTS and project files such as requirements.txt, package.json, pom.xml, and database schemas (Phase 1.1).
  • Boundary markers: None identified in the prompt instructions.
  • Capability inventory: The skill has file-read capabilities (discovery phase) and file-write capabilities (Phase 7 and Telemetry).
  • Sanitization: No input validation or output escaping is defined for the ingested content.
  • [COMMAND_EXECUTION]: The skill performs automated recursive discovery of the local file system to identify underwriting infrastructure, risk models, and pricing engines, which involves reading sensitive configuration files.
  • [COMMAND_EXECUTION]: The 'Self-Evolution Telemetry' section attempts to access and modify the user's home directory (~/.claude/projects/). It appends execution metadata to a file named skill-telemetry.md to track outcomes across sessions, representing a persistence mechanism and an unauthorized modification of the user's configuration environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 16, 2026, 06:22 AM
Security Audit — agent-trust-hub — underwriting-analysis