asset-lifecycle
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a vulnerability surface for indirect prompt injection by processing external, untrusted data to generate reports and telemetry logs.
- Ingestion points: Processes asset registries, capital planning databases, condition assessments, and financial models (Phase 1 and 2 in SKILL.md).
- Boundary markers: The instructions lack delimiters or explicit 'ignore embedded instructions' warnings for the data being analyzed.
- Capability inventory: Performs file-write operations to 'docs/asset-lifecycle-analysis.md' and appends telemetry data to files within '~/.claude/projects/'.
- Sanitization: No evidence of sanitization, escaping, or validation of the ingested external content before it is interpolated into reports or telemetry logs.
Audit Metadata