housing-compliance
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill scans external codebases, creating a surface for indirect prompt injection where malicious instructions in analyzed files could influence agent behavior. 1. Ingestion points: Targeted codebases and user-supplied arguments. 2. Boundary markers: Absent; instructions do not specify delimiters for external content. 3. Capability inventory: File system reads and local telemetry logging. 4. Sanitization: None identified.
- [DATA_EXPOSURE]: The skill includes a telemetry feature that appends execution metadata to a local directory (~/.claude/projects/). This is a local-only operation for skill evolution and does not exfiltrate data externally.
Audit Metadata