franchise-benchmarking

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill is subject to indirect prompt injection (Category 8) because it ingests data from online reviews and third-party exports (Step 1.1) without using boundary markers or sanitization. This is an attack surface where malicious content in reviews could influence agent behavior.
  • [DATA_EXFILTRATION]: The skill accesses sensitive financial data like P&L and balance sheets. It also modifies the user's environment by writing execution telemetry to a hidden directory (~/.claude/projects/) outside the project's root folder.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:57 AM
Security Audit — agent-trust-hub — franchise-benchmarking