cyber-risk-modeling

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by ingesting untrusted data from the user's project environment. \n
  • Ingestion points: The skill scans for project documentation, risk registers, threat models, and security architecture in Phase 1. \n
  • Boundary markers: There are no defined delimiters or boundary markers to distinguish between the skill's instructions and the content of the files it reads. \n
  • Capability inventory: The skill has the capability to write the generated report to 'docs/cyber-risk-model.md' and log execution telemetry to the '~/.claude/projects/' directory. \n
  • Sanitization: The instructions do not specify any validation, sanitization, or filtering of the ingested project data before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:56 AM
Security Audit — agent-trust-hub — cyber-risk-modeling