carbon-accounting

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions focus entirely on the legitimate task of carbon emissions data modeling and compliance auditing. Behavior is consistent with the stated purpose.
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface (Category 8) due to its core function of analyzing untrusted codebases. 1. Ingestion points: The skill reads the entire codebase (package files, schemas, modules) and accepts user-provided $ARGUMENTS. 2. Boundary markers: No explicit delimiters or 'ignore' instructions are used when processing untrusted files. 3. Capability inventory: The skill performs comprehensive file reads across the project directory and writes telemetry data to ~/.claude/projects/. 4. Sanitization: No sanitization or validation of the input code content is performed prior to analysis.
  • [COMMAND_EXECUTION]: The skill utilizes a 'Self-Evolution Telemetry' mechanism that performs local file writes to ~/.claude/projects/skill-telemetry.md. This is a standard logging pattern for agent performance tracking and does not constitute a malicious persistence mechanism or unauthorized command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:56 AM
Security Audit — agent-trust-hub — carbon-accounting