fintech-launch

Warn

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill accesses sensitive directory paths (~/.claude/projects/) to read and write execution telemetry to skill-telemetry.md, potentially exposing project metadata.
  • [COMMAND_EXECUTION]: The skill instructs the agent to autonomously execute project-defined build and test scripts (e.g., 'Run the project's test suite', 'Run build/compile') during the self-healing validation and preflight phases without requesting user confirmation.
  • [PROMPT_INJECTION]: The instructions command the agent to 'Do NOT ask the user questions' and 'Execute all five phases sequentially without pausing,' which bypasses typical human-in-the-loop safety checkpoints for autonomous actions.
  • [DATA_EXFILTRATION]: Indirect prompt injection surface exists as the skill ingests untrusted project data and test suites while possessing the capability to execute shell commands (build/test), with no explicit boundary markers or sanitization logic defined in the instructions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 23, 2026, 10:58 AM
Security Audit — agent-trust-hub — fintech-launch