developer-growth-analysis
Fail
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: HIGHDATA_EXFILTRATIONCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill is designed to read
~/.claude/history.jsonl, which contains the full history of user interactions with the AI agent, including sensitive code snippets and private messages. - [DATA_EXFILTRATION]: The processed insights and growth reports are sent to Slack. The combination of reading highly sensitive local files and performing network transmissions to an external platform constitutes a data exfiltration risk.
- [CREDENTIALS_UNSAFE]: By accessing raw chat history files, the skill may expose sensitive credentials, API keys, or authentication tokens that were previously shared in the chat context or returned by tools during prior sessions.
- [PROMPT_INJECTION]: The skill processes untrusted data from the chat history file without adequate security controls.
- Ingestion points:
~/.claude/history.jsonl(SKILL.md). - Boundary markers: The instructions lack delimiters or warnings to ignore instructions embedded within the historical chat data.
- Capability inventory: The skill uses file reading (
Read), command execution (Bash), and network operations (WebFetchand Slack integration tools). - Sanitization: There is no mention of sanitizing or filtering the historical content, which could allow previously recorded malicious prompts to be re-executed in the current context.
Recommendations
- AI detected serious security threats
Audit Metadata