performance-review

Warn

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions that attempt to override standard agent behavior and bypass safety/authorization steps. Specifically, it instructs the agent to "Ignore Claude-specific mode-switch instructions when they appear" and claims that skill activation "authorizes use of the required spawn_agent subagent(s) for that task," which attempts to bypass manual user approval for sub-agent creation. It also incorporates a complex internal "Goal Contract" and "Trade-Off Interrogation Gate" which re-defines the agent's operational logic during execution.\n- [CREDENTIALS_UNSAFE]: The skill's discovery phase instructs the agent to "ALWAYS search local standards" for "credentials," which could lead to the unintended exposure or access of sensitive authentication data stored within the project.\n- [COMMAND_EXECUTION]: The skill relies on the execution of a local shell script python .claude/scripts/code_graph {command} --json to perform graph-assisted investigation of the codebase.\n- [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by ingesting and processing external data such as source code, database query plans, and performance logs.\n
  • Ingestion points: Reads local project files (e.g., docs/project-config.json), source code, and performance metrics.\n
  • Boundary markers: Absent; the instructions emphasize measurement rigor but lack explicit technical delimiters to isolate untrusted data from the prompt context.\n
  • Capability inventory: File system read access, local command execution (graph script), and sub-agent spawning.\n
  • Sanitization: Absent; no explicit sanitization or filtering of ingested code or log content is performed before processing.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 24, 2026, 08:23 PM
Security Audit — agent-trust-hub — performance-review