contract-risk

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs local analysis of source code, package manifests, and configuration files to audit contract lifecycle logic. It identifies dependencies and maps architectural modules without executing remote code or making unauthorized network requests.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface typical of code analysis tools that ingest untrusted third-party content. It lacks explicit boundary markers for separating codebase data from internal instructions.
  • Ingestion points: The agent is instructed to "Investigate the entire codebase thoroughly," which includes all files in the target directory.
  • Boundary markers: There are no explicit delimiters or protective instructions provided to prevent the agent from obeying commands embedded in the audited source code or data files.
  • Capability inventory: The skill is authorized to read local files and append execution metadata to a local telemetry file in the ~/.claude/projects/ directory.
  • Sanitization: No sanitization or filtering is applied to the content read from the codebase before it is integrated into the agent's analysis context.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:56 AM
Security Audit — agent-trust-hub — contract-risk