insurance-claims

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect prompt injection surface detected. The skill is designed to systematically ingest and evaluate an entire codebase, which constitutes untrusted data that could contain malicious instructions.
  • Ingestion points: Files in the current working directory across all phases (FNOL, Investigation, Adjustment, etc.).
  • Boundary markers: Absent; the instructions do not wrap external content in delimiters or include 'ignore embedded instructions' warnings.
  • Capability inventory: Read access to the local filesystem and write access to a local telemetry log file at ~/.claude/projects/skill-telemetry.md.
  • Sanitization: Absent; there is no logic to escape or validate data retrieved from the codebase before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:57 AM
Security Audit — agent-trust-hub — insurance-claims