care-burnout-audit

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted codebase data through the $ARGUMENTS variable, creating an indirect prompt injection surface where instructions embedded in the audited code could influence agent behavior. Ingestion points: Codebase files specified in $ARGUMENTS. Boundary markers: Absent. Capability inventory: File-read (codebase analysis) and file-write (report generation and telemetry). Sanitization: Absent.
  • [COMMAND_EXECUTION]: The skill performs local file system operations, specifically writing audit results to a 'docs' directory and appending telemetry data to a specific project path in the user's home directory. Evidence: Instructions to write review to 'docs/care-burnout-audit.md' and append metadata to '~/.claude/projects/skill-telemetry.md'.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:58 AM
Security Audit — agent-trust-hub — care-burnout-audit