scout-pro

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill is designed to read and analyze potentially sensitive data from the agent's internal state and local user directories.
  • Evidence:
  • The workflow in SKILL.md specifies reading session history and context from ~/.claude/ and its subdirectories (rules/session-context.md, projects/).
  • The skill maintains and writes to a persistent log file at ~/.claude/scout-pro-usage-log.json to track recommendations and outcomes.
  • It accesses a specific local directory structure at /Users/gabe/claude-skills/ to inventory available tools.
  • The combination of access to sensitive session data and network tools (WebFetch, WebSearch) creates a technical surface for data exfiltration, although no specific malicious exfiltration commands were found.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple sources which could contain hidden instructions designed to influence the agent's behavior or workflow recommendations.
  • Ingestion points: The skill ingests data from external websites via WebFetch and WebSearch, as well as historical data from ~/.claude/projects/ memory files and the full conversation history.
  • Boundary markers: The instructions do not define explicit boundary markers or XML-style delimiters to isolate external content from the system prompt.
  • Capability inventory: The skill has the capability to read local files, perform network requests, and write to local configuration/log files (scout-pro-usage-log.json, chain-config.yaml).
  • Sanitization: There is no evidence of sanitization or filtering logic applied to external data before it is incorporated into the context analysis process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 12:50 AM
Security Audit — agent-trust-hub — scout-pro