procurement-analysis

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection because it is designed to ingest and analyze a wide variety of external procurement records and codebase content without pre-defined boundary markers or sanitization logic.
  • Ingestion points: The skill instructions (Phase 1) direct the agent to read the codebase and comprehensive data from procurement platforms such as SAP Ariba, Coupa, and Jaggaer.
  • Boundary markers: Absent. The skill does not provide specific delimiters or instructions to ignore embedded commands within the ingested data.
  • Capability inventory: The skill has the capability to write reports to the 'docs/' directory and append execution metadata to 'skill-telemetry.md' in the '~/.claude/projects/' directory (Phase 7 and Telemetry sections).
  • Sanitization: Absent. There is no instruction to validate or escape external content before processing.
  • [SAFE]: The skill accesses sensitive financial and business data, including vendor master files (banking, tax IDs) and contract terms, which is a required function for procurement spend analytics.
  • [SAFE]: The skill records execution telemetry in the '~/.claude/projects/' hidden directory. This interaction is restricted to the local environment and serves as a performance tracking and self-improvement mechanism for the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:58 AM
Security Audit — agent-trust-hub — procurement-analysis