dum-dum
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill's collection logic in
collect.pyreads user session transcripts from~/.claude/projects/. These files contain comprehensive histories of user prompts and AI responses, which may expose private information to the agent context during quality analysis.\n- [COMMAND_EXECUTION]: Theprobe.pyscript usessubprocess.run()to execute shell commands that invoke thescillmutility. This cross-component communication enables the skill to launch external processes for model evaluation.\n- [EXTERNAL_DOWNLOADS]: Thedashboard.pyscript generates a visualization dashboard that references the D3.js library fromhttps://d3js.org/d3.v7.min.js. This resource is fetched from a well-known and trusted service provider.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted session data from transcripts, creating a vulnerability surface for indirect prompt injection.\n - Ingestion points:
collect.pyreads session history from JSONL files in~/.claude/projects/.\n - Boundary markers: Absent. The skill parses raw message content from logs without delimiters to distinguish between data and instructions.\n
- Capability inventory: The skill maintains shell execution capabilities via its interaction with the
scillmtool.\n - Sanitization: None. Extracted transcript content is stored and processed without filtering for embedded instructions.
Audit Metadata