environmental-compliance
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to investigate an entire codebase thoroughly (Phase 1), reading multiple configuration and source files to identify tech stacks and regulatory applicability. It lacks boundary markers or instructions to disregard potential commands found within the scanned files, which creates an attack surface for indirect prompt injection.
- Ingestion points: Target codebase files such as package.json, requirements.txt, go.mod, Gemfile, and pom.xml.
- Boundary markers: Absent.
- Capability inventory: File reading and local file writing for telemetry tracking in ~/.claude/projects/.
- Sanitization: None performed on the ingested file data.
Audit Metadata