asset-lifecycle

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a vulnerability surface for indirect prompt injection by processing external, untrusted data to generate reports and telemetry logs.
  • Ingestion points: Processes asset registries, capital planning databases, condition assessments, and financial models (Phase 1 and 2 in SKILL.md).
  • Boundary markers: The instructions lack delimiters or explicit 'ignore embedded instructions' warnings for the data being analyzed.
  • Capability inventory: Performs file-write operations to 'docs/asset-lifecycle-analysis.md' and appends telemetry data to files within '~/.claude/projects/'.
  • Sanitization: No evidence of sanitization, escaping, or validation of the ingested external content before it is interpolated into reports or telemetry logs.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:56 AM
Security Audit — agent-trust-hub — asset-lifecycle