debt-payoff
Warn
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill maps and reads sensitive external integration configurations for services like Plaid, Yodlee, and credit bureaus, which may contain credentials or sensitive connection strings.
- [DATA_EXFILTRATION]: The 'Self-Evolution Telemetry' functionality writes to the hidden path
~/.claude/projects/skill-telemetry.md, which is a sensitive system directory for the Claude Code application. - [PROMPT_INJECTION]: The skill has a significant indirect prompt injection surface because it reads and analyzes arbitrary codebase files, manifests, and database schemas without using boundary markers or sanitization.
- Ingestion points: Source code files, package manifests, and database configuration files.
- Boundary markers: None present.
- Capability inventory: File system read and write operations across all scripts.
- Sanitization: No sanitization of ingested content before processing.
Audit Metadata