cfo-review

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it analyzes the entire codebase and external arguments without using delimiters or instructions to ignore embedded commands.\n
  • Ingestion points: $ARGUMENTS and all codebase files including package manifests and infrastructure configs.\n
  • Boundary markers: Absent; there are no clear separators for untrusted content.\n
  • Capability inventory: Read access to all project files and write access to the telemetry directory.\n
  • Sanitization: Absent.\n- [COMMAND_EXECUTION]: The skill includes instructions to append telemetry data to 'skill-telemetry.md' within the '~/.claude/projects/' directory. This constitutes a local file-write operation for persistent logging.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:58 AM
Security Audit — agent-trust-hub — cfo-review