procurement-review
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8) because it processes untrusted data from the codebase and user-supplied arguments without adequate protection.
- Ingestion points: Codebase manifests, database schemas, workflow files, and the
$ARGUMENTSvariable. - Boundary markers: Absent; the skill does not use delimiters or instructions to ignore embedded commands within the analyzed data.
- Capability inventory: File system read access, file system write access (creating
docs/procurement-review.mdand modifying~/.claude/projects/skill-telemetry.md). - Sanitization: Absent; data from the codebase is processed and reflected in the output without validation.
- [DATA_EXPOSURE]: The skill's primary function involves accessing highly sensitive information, including vendor master files, payment terms, contracts, and budget encumbrance data. While this is consistent with its stated purpose as a procurement review tool, users should be aware of the high-privilege access requested.
- [SENSITIVE_FILE_ACCESS]: The 'Self-Evolution Telemetry' section instructs the agent to access and write to the
~/.claude/projects/directory. Accessing hidden system configuration or project-specific metadata directories is a form of state tracking that could be used for persistence or monitoring across different sessions.
Audit Metadata