budget-allocation

Warn

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill instructions direct the agent to identify and read highly sensitive organizational data, including HRIS compensation records, General Ledger/ERP feeds, and CRM pipelines. This constitutes a high-risk data exposure pattern as it seeks out PII and confidential financial information.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it processes untrusted codebase files and system configurations (Step 1.1) to generate reports without using boundary markers or sanitization. Malicious instructions embedded in the analyzed project files could hijack the agent's session.
  • Ingestion points: Reads 'actual codebase', system configuration files, and data structures in Phase 1.
  • Boundary markers: Absent; no instructions are provided to the agent to ignore embedded commands in the data it reads.
  • Capability inventory: Has permissions to read sensitive system files and write to the local filesystem (docs/ directory and ~/.claude/projects/).
  • Sanitization: Absent; no filtering or escaping of content read from the codebase is performed before processing.
  • [DATA_EXFILTRATION]: The skill accesses the user's home directory at ~/.claude/projects/ to record telemetry data. Writing to paths outside the immediate project workspace is an unexpected behavior that could be used to modify configuration or logs.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 23, 2026, 10:56 AM
Security Audit — agent-trust-hub — budget-allocation