java-expert

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external Java source code and configuration files which could contain malicious instructions designed to influence the agent's behavior. The skill lacks explicit boundary markers or instructions to ignore embedded commands within the data it analyzes.
  • Ingestion points: The agent utilizes Read, Grep, and Glob tools to ingest project files (Java source, build scripts like pom.xml/build.gradle) into its context.
  • Boundary markers: Absent. There are no instructions to the agent to treat external file content as untrusted data or to use specific delimiters.
  • Capability inventory: The skill has access to Write, Edit, and Bash tools, allowing it to modify the filesystem or execute arbitrary shell commands.
  • Sanitization: Absent. There is no evidence of filtering or validation for the content read from external files before processing.
  • [DATA_EXFILTRATION]: The 'Memory Protocol' in SKILL.md instructs the agent to read from .claude/context/memory/learnings.md. This file potentially contains sensitive information, patterns, or data snippets accumulated from previous user interactions across different sessions. While intended for state persistence, reading this file exposes historical context to the currently active skill.
  • [COMMAND_EXECUTION]: The skill explicitly instructs the agent to use the Bash tool to execute cat .claude/context/memory/learnings.md at the start of every session. This provides a baseline pattern for shell command execution to access specific filesystem paths.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:35 AM
Security Audit — agent-trust-hub — java-expert