apparel-demand

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a significant surface for indirect prompt injection by design, as its primary function is to ingest and analyze untrusted project data.
  • Ingestion points: The skill reads the entire codebase, system configurations, POS transaction data, and customer purchase history (SKILL.md).
  • Boundary markers: There are no specified delimiters or instructions for the agent to ignore or isolate instructions that might be embedded within the files it reads.
  • Capability inventory: The agent is granted capabilities to read project files and write to both the docs/ directory and the agent's internal project memory at ~/.claude/projects/ (SKILL.md).
  • Sanitization: No sanitization or validation logic is defined to prevent the agent from obeying instructions found inside the analyzed data.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:56 AM
Security Audit — agent-trust-hub — apparel-demand