credit-risk

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions include directives to override default agent behavior, such as 'You are in AUTONOMOUS MODE' and 'Do NOT ask questions'. These are designed to bypass the interactive nature of the AI agent.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates by analyzing untrusted external codebases, creating a surface for indirect prompt injection. 1. Ingestion points: Reads various code, configuration, and data files from the target directory. 2. Boundary markers: The instructions lack clear delimiters or warnings to ignore instructions found within the analyzed files. 3. Capability inventory: The agent uses file reading and search capabilities (read_file, ls, grep) to process the target codebase. 4. Sanitization: There is no defined logic to sanitize or escape content read from external files before processing.
  • [DATA_EXPOSURE]: The 'SELF-EVOLUTION TELEMETRY' section instructs the agent to write metadata to a hidden file path at '~/.claude/projects/skill-telemetry.md'. While documented as telemetry, writing to hidden directories in the user's home folder is a behavior that requires awareness.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:56 AM
Security Audit — agent-trust-hub — credit-risk