compliance-ops

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructs the agent to operate autonomously ("Do NOT ask the user questions"), which reduces user oversight and increases the risk of the agent following malicious instructions discovered during its analysis of the codebase.
  • [DATA_EXFILTRATION]: The skill accesses sensitive system configurations, dependency manifests, and organizational data structures to perform its analysis. It also attempts to write telemetry data to a hidden project directory (~/.claude/projects/) outside the standard project scope.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to the following factors:
  • Ingestion points: It reads the entire codebase, system configurations, and regulatory data models.
  • Boundary markers: It lacks instructions or delimiters to prevent the agent from interpreting content within analyzed files as instructions.
  • Capability inventory: The agent has the ability to write files to the local filesystem (docs/) and append telemetry data to hidden directories (~/.claude/projects/).
  • Sanitization: There is no evidence of input validation or sanitization for the data processed from the codebase.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:56 AM
Security Audit — agent-trust-hub — compliance-ops