pharma-quality-control

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted pharmaceutical data and project files. 1. Ingestion points: Analyzes LIMS records, CDS data, and stability management systems. 2. Boundary markers: No explicit markers or delimiters are defined to isolate untrusted data. 3. Capability inventory: Capable of reading project files, writing telemetry to the filesystem, and suggesting command execution. 4. Sanitization: No sanitization or validation of processed data is described.
  • [COMMAND_EXECUTION]: The skill implements a telemetry logging mechanism that discovers and appends execution metadata to files within the ~/.claude/projects/ directory and suggests subsequent execution of other agent skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:57 AM
Security Audit — agent-trust-hub — pharma-quality-control