apparel-demand
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a significant surface for indirect prompt injection by design, as its primary function is to ingest and analyze untrusted project data.
- Ingestion points: The skill reads the entire codebase, system configurations, POS transaction data, and customer purchase history (SKILL.md).
- Boundary markers: There are no specified delimiters or instructions for the agent to ignore or isolate instructions that might be embedded within the files it reads.
- Capability inventory: The agent is granted capabilities to read project files and write to both the
docs/directory and the agent's internal project memory at~/.claude/projects/(SKILL.md). - Sanitization: No sanitization or validation logic is defined to prevent the agent from obeying instructions found inside the analyzed data.
Audit Metadata