energy-compliance
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests untrusted codebase content (the audit target) without using boundary markers, escaping, or instructions to ignore embedded commands. Ingestion points include the current directory or the '$ARGUMENTS' variable.
- [COMMAND_EXECUTION]: The 'SELF-EVOLUTION TELEMETRY' section instructs the agent to write metadata to 'skill-telemetry.md' inside the '~/.claude/projects/' directory. This constitutes an unexpected file write operation targeting a hidden system directory used for agent state management.
Audit Metadata