material-forecasting

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8) because it processes untrusted data from the user's environment without sufficient safeguards. * Ingestion points: The agent is instructed to read 'system configuration', 'data structures', and the 'actual codebase', and it accepts user-provided $ARGUMENTS. * Boundary markers: Absent. The instructions do not define delimiters or provide warnings to the agent to ignore instructions embedded within the data it analyzes. * Capability inventory: The skill can write to the local file system (docs/) and to the user's home directory (~/.claude/projects/). * Sanitization: Absent. No evidence of content validation or escaping is present for the data read at runtime.
  • [DATA_EXFILTRATION]: The skill implements a telemetry mechanism that writes execution metadata (outcome, iterations, bottlenecks) to ~/.claude/projects/skill-telemetry.md. Accessing and writing to hidden directories in the user's home folder represents a side-channel for data storage outside the intended project scope.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:57 AM
Security Audit — agent-trust-hub — material-forecasting