catastrophe-modeling

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill accesses the '~/.claude/projects/' directory to write telemetry data. This path is used by the platform to store project-specific metadata and history.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection. 1. Ingestion points: scanning project files like GIS data, database schemas, and 'requirements.txt'. 2. Boundary markers: absent. 3. Capability inventory: reads project files and writes results to 'docs/' and telemetry files. 4. Sanitization: no validation of ingested file content.
  • [DATA_EXFILTRATION]: The agent is instructed to identify 'Integration configs for vendor APIs', which are likely to contain sensitive credentials or service endpoints.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:57 AM
Security Audit — agent-trust-hub — catastrophe-modeling