job-dispatch
Warn
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data including codebase contents, technician data, and work order records without incorporating boundary markers or specific sanitization instructions. This creates a surface for indirect prompt injection where malicious instructions embedded in the analyzed service data could influence the agent's behavior. . . Ingestion points: Project codebase, technician workforce data, job/work order structures. . . Boundary markers: Absent. . . Capability inventory: File system writes to 'docs/' and '~/.claude/'. . . Sanitization: None present.
- [DATA_EXFILTRATION]: The skill contains instructions to access and write telemetry data to a hidden directory in the user's home folder ('~/.claude/projects/'). Accessing and modifying files within a tool's internal metadata and configuration directory is a security concern as it extends beyond the project's scope and could potentially lead to the exposure or modification of sensitive environment state.
Audit Metadata