compliance-suite
Warn
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: Accesses the agent's internal metadata directory at
~/.claude/projects/to verify project paths and record execution telemetry inskill-telemetry.md. - [COMMAND_EXECUTION]: Instructs the agent to simulate security attacks (penetration testing) and automatically implement and commit code fixes for discovered vulnerabilities.
- [PROMPT_INJECTION]: Employs directives to operate autonomously and restrict user feedback ('Do NOT ask the user questions'), potentially concealing malicious or erroneous actions.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it reads and processes untrusted codebase files and dependency manifests without boundary markers while maintaining the ability to commit code changes.
- Ingestion points: Project source code, dependency manifests, and user-supplied arguments.
- Boundary markers: None identified to separate instructions from analyzed data.
- Capability inventory: Sub-agent management, penetration testing, and repository write/commit access.
- Sanitization: No evidence of validation or sanitization of ingested content.
Audit Metadata