batch-optimization

Warn

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions include steps to access and write to ~/.claude/projects/ for telemetry purposes. This involves interacting with the filesystem in a location that stores agent-specific metadata and project histories, potentially allowing for cross-project data persistence or side-channel information leakage.
  • [DATA_EXFILTRATION]: The skill performs discovery of sensitive internal infrastructure including database schemas, API endpoints, and Manufacturing Execution System (MES) connectors such as OSIsoft PI, Wonderware, and DeltaV. This data, while relevant to manufacturing analysis, exposes technical architecture details to the agent context.
  • [PROMPT_INJECTION]: The skill demonstrates a surface for indirect prompt injection (Category 8).
  • Ingestion points: Processes batch production records, MES data, CSV/JSON/Parquet files, and report templates found in the project (SKILL.md).
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are specified for the ingested data.
  • Capability inventory: Performs file writing to docs/batch-optimization-analysis.md (SKILL.md).
  • Sanitization: No evidence of sanitization or validation of the ingested external content before it is processed or written to the report.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 23, 2026, 10:56 AM
Security Audit — agent-trust-hub — batch-optimization