compliance-suite

Warn

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: Accesses the agent's internal metadata directory at ~/.claude/projects/ to verify project paths and record execution telemetry in skill-telemetry.md.
  • [COMMAND_EXECUTION]: Instructs the agent to simulate security attacks (penetration testing) and automatically implement and commit code fixes for discovered vulnerabilities.
  • [PROMPT_INJECTION]: Employs directives to operate autonomously and restrict user feedback ('Do NOT ask the user questions'), potentially concealing malicious or erroneous actions.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it reads and processes untrusted codebase files and dependency manifests without boundary markers while maintaining the ability to commit code changes.
  • Ingestion points: Project source code, dependency manifests, and user-supplied arguments.
  • Boundary markers: None identified to separate instructions from analyzed data.
  • Capability inventory: Sub-agent management, penetration testing, and repository write/commit access.
  • Sanitization: No evidence of validation or sanitization of ingested content.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 23, 2026, 10:58 AM
Security Audit — agent-trust-hub — compliance-suite