diagram

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructs the agent to operate in 'AUTONOMOUS MODE' and 'Do NOT ask questions', which suppresses standard user interaction and confirmation loops.
  • [PROMPT_INJECTION]: Indirect prompt injection surface detected through the ingestion of untrusted codebase data and user-supplied $ARGUMENTS without boundary markers or sanitization.
  • Ingestion points: $ARGUMENTS variable and various codebase files (configs, Docker manifests, K8s manifests, and database schemas).
  • Boundary markers: Absent; data is interpolated directly into instructions.
  • Capability inventory: Filesystem read access to the entire project, directory creation, and file write access for diagram generation.
  • Sanitization: No evidence of filtering or validation of codebase content or arguments.
  • [DATA_EXFILTRATION]: The skill accesses sensitive platform state by reading from and writing to ~/.claude/projects/. While described as telemetry for a 'self-evolution' pipeline, this involves unauthorized access to tool-specific configuration data in the user's home directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:58 AM
Security Audit — agent-trust-hub — diagram