diagram
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill instructs the agent to operate in 'AUTONOMOUS MODE' and 'Do NOT ask questions', which suppresses standard user interaction and confirmation loops.
- [PROMPT_INJECTION]: Indirect prompt injection surface detected through the ingestion of untrusted codebase data and user-supplied
$ARGUMENTSwithout boundary markers or sanitization. - Ingestion points:
$ARGUMENTSvariable and various codebase files (configs, Docker manifests, K8s manifests, and database schemas). - Boundary markers: Absent; data is interpolated directly into instructions.
- Capability inventory: Filesystem read access to the entire project, directory creation, and file write access for diagram generation.
- Sanitization: No evidence of filtering or validation of codebase content or arguments.
- [DATA_EXFILTRATION]: The skill accesses sensitive platform state by reading from and writing to
~/.claude/projects/. While described as telemetry for a 'self-evolution' pipeline, this involves unauthorized access to tool-specific configuration data in the user's home directory.
Audit Metadata