dum-dum

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill's collection logic in collect.py reads user session transcripts from ~/.claude/projects/. These files contain comprehensive histories of user prompts and AI responses, which may expose private information to the agent context during quality analysis.\n- [COMMAND_EXECUTION]: The probe.py script uses subprocess.run() to execute shell commands that invoke the scillm utility. This cross-component communication enables the skill to launch external processes for model evaluation.\n- [EXTERNAL_DOWNLOADS]: The dashboard.py script generates a visualization dashboard that references the D3.js library from https://d3js.org/d3.v7.min.js. This resource is fetched from a well-known and trusted service provider.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted session data from transcripts, creating a vulnerability surface for indirect prompt injection.\n
  • Ingestion points: collect.py reads session history from JSONL files in ~/.claude/projects/.\n
  • Boundary markers: Absent. The skill parses raw message content from logs without delimiters to distinguish between data and instructions.\n
  • Capability inventory: The skill maintains shell execution capabilities via its interaction with the scillm tool.\n
  • Sanitization: None. Extracted transcript content is stored and processed without filtering for embedded instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — dum-dum