debt-payoff

Warn

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill maps and reads sensitive external integration configurations for services like Plaid, Yodlee, and credit bureaus, which may contain credentials or sensitive connection strings.
  • [DATA_EXFILTRATION]: The 'Self-Evolution Telemetry' functionality writes to the hidden path ~/.claude/projects/skill-telemetry.md, which is a sensitive system directory for the Claude Code application.
  • [PROMPT_INJECTION]: The skill has a significant indirect prompt injection surface because it reads and analyzes arbitrary codebase files, manifests, and database schemas without using boundary markers or sanitization.
  • Ingestion points: Source code files, package manifests, and database configuration files.
  • Boundary markers: None present.
  • Capability inventory: File system read and write operations across all scripts.
  • Sanitization: No sanitization of ingested content before processing.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 23, 2026, 10:56 AM
Security Audit — agent-trust-hub — debt-payoff