environmental-compliance

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to investigate an entire codebase thoroughly (Phase 1), reading multiple configuration and source files to identify tech stacks and regulatory applicability. It lacks boundary markers or instructions to disregard potential commands found within the scanned files, which creates an attack surface for indirect prompt injection.
  • Ingestion points: Target codebase files such as package.json, requirements.txt, go.mod, Gemfile, and pom.xml.
  • Boundary markers: Absent.
  • Capability inventory: File reading and local file writing for telemetry tracking in ~/.claude/projects/.
  • Sanitization: None performed on the ingested file data.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:59 AM
Security Audit — agent-trust-hub — environmental-compliance