facilities-energy
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill directly interpolates user-provided arguments into the analysis target, which could lead to direct prompt injection. Evidence: 'TARGET: $ARGUMENTS' in SKILL.md.
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it is designed to analyze data from external building and utility systems.
- Ingestion points: Building Management Systems (BMS/BAS), utility APIs, and energy management information systems (SKILL.md).
- Boundary markers: The instructions do not define explicit delimiters or include safety warnings to ignore instructions embedded within the processed data.
- Capability inventory: The agent is directed to write reports to the local file system (docs/facilities-energy-analysis.md) and record execution telemetry (~/.claude/projects/skill-telemetry.md).
- Sanitization: No input validation or sanitization is specified for the data being analyzed.
Audit Metadata