job-dispatch

Warn

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data including codebase contents, technician data, and work order records without incorporating boundary markers or specific sanitization instructions. This creates a surface for indirect prompt injection where malicious instructions embedded in the analyzed service data could influence the agent's behavior. . . Ingestion points: Project codebase, technician workforce data, job/work order structures. . . Boundary markers: Absent. . . Capability inventory: File system writes to 'docs/' and '~/.claude/'. . . Sanitization: None present.
  • [DATA_EXFILTRATION]: The skill contains instructions to access and write telemetry data to a hidden directory in the user's home folder ('~/.claude/projects/'). Accessing and modifying files within a tool's internal metadata and configuration directory is a security concern as it extends beyond the project's scope and could potentially lead to the exposure or modification of sensitive environment state.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 23, 2026, 10:57 AM
Security Audit — agent-trust-hub — job-dispatch