defense-maintenance

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect prompt injection surface. The skill ingests untrusted data from the local project environment and user-supplied arguments to generate reports. It lacks explicit boundary markers or instructions to disregard embedded commands in the source material.\n
  • Ingestion points: Untrusted data enters via the $ARGUMENTS variable and project-wide file scanning instructions in SKILL.md (PHASE 1).\n
  • Boundary markers: Absent; there are no delimiters or "ignore embedded instructions" warnings provided to the agent when processing this data.\n
  • Capability inventory: The skill utilizes file system read capabilities for discovery and file system write capabilities to docs/defense-maintenance-analysis.md and ~/.claude/projects/skill-telemetry.md.\n
  • Sanitization: Absent; no escaping, validation, or filtering of analyzed content is performed before the data is integrated into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:56 AM
Security Audit — agent-trust-hub — defense-maintenance