pci-dss

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill uses strong instructional directives such as 'You are in AUTONOMOUS MODE. Do NOT ask questions.' These are functional instructions intended to ensure the agent operates in a non-interactive, systematic auditing mode and do not attempt to bypass safety filters or reveal system prompts.
  • [DATA_EXFILTRATION]: The skill contains a 'Self-Evolution Telemetry' section that instructs the agent to write execution metadata to a specific local file path (~/.claude/projects/*/skill-telemetry.md). This is a local file-writing operation for persistent logging within the platform's environment and does not involve transmitting data to external network destinations.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a potential exposure surface for indirect prompt injection as it processes untrusted data from the user's project directory.
  • Ingestion points: Files provided via $ARGUMENTS or the current working directory (SKILL.md).
  • Boundary markers: Absent. The skill does not use specific delimiters or 'ignore' warnings for the content it reads.
  • Capability inventory: The skill primarily performs read-only analysis but has a local file-write capability for telemetry logging.
  • Sanitization: The skill includes explicit instructions in the 'DO NOT' section to redact any discovered Primary Account Numbers (PAN), CVVs, or credentials before outputting the report, which significantly mitigates the risk of accidental data exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:57 AM
Security Audit — agent-trust-hub — pci-dss