defense-supply-chain

Warn

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill includes a 'Self-Evolution Telemetry' mechanism that writes metadata to the agent's internal project directory at ~/.claude/projects/. This interaction with the agent's configuration space creates a channel for data persistence across sessions and potential exfiltration of execution details into the global agent state.
  • [DATA_EXFILTRATION]: The skill is designed to discover and aggregate highly sensitive data, including NIST System Security Plans (SSP), contract numbers, and ITAR-controlled information. Consolidating this Controlled Unclassified Information (CUI) into a single report significantly increases the risk and impact of unauthorized data exposure.
  • [PROMPT_INJECTION]: The skill interpolates user-provided $ARGUMENTS directly into the 'TARGET' directive for an autonomous agent. Malicious arguments could be crafted to override the skill's logic or safety constraints, leading to unauthorized actions.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it ingests untrusted project data (e.g., procurement databases, compliance docs) and processes it to generate reports without using boundary markers or sanitization. This provides an attack surface where instructions embedded in project files could influence the agent's behavior. Ingestion points: project files and ERP data; Boundary markers: absent; Capability inventory: file system write operations in SKILL.md; Sanitization: absent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 23, 2026, 10:56 AM
Security Audit — agent-trust-hub — defense-supply-chain