audit
Warn
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill instructions explicitly direct the agent to read the
.envfile to verify the presence of API keys and connection mechanisms. Accessing environment files is a sensitive operation as they are a primary location for plaintext credentials and secrets. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted project data, which creates a surface for indirect prompt injection attacks.
- Ingestion points: The skill reads
CLAUDE.md,MEMORY.md, and multiple files within the.claude/skills/and.claude/agents/directories. - Boundary markers: There are no instructions to wrap ingested content in delimiters or ignore potential embedded instructions.
- Capability inventory: The skill has the capability to write files to the local filesystem (saving audit reports to the
audits/directory). - Sanitization: The skill does not implement any sanitization or validation for the content it reads from the project files.
- [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the dynamic context injection pattern
!date +%Y-%m-%din theSKILL.mdfile. This triggers shell command execution at load time to populate the date field. While the specific command is benign, the use of this syntax allows for pre-execution shell operations.
Audit Metadata