procurement-review

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8) because it processes untrusted data from the codebase and user-supplied arguments without adequate protection.
  • Ingestion points: Codebase manifests, database schemas, workflow files, and the $ARGUMENTS variable.
  • Boundary markers: Absent; the skill does not use delimiters or instructions to ignore embedded commands within the analyzed data.
  • Capability inventory: File system read access, file system write access (creating docs/procurement-review.md and modifying ~/.claude/projects/skill-telemetry.md).
  • Sanitization: Absent; data from the codebase is processed and reflected in the output without validation.
  • [DATA_EXPOSURE]: The skill's primary function involves accessing highly sensitive information, including vendor master files, payment terms, contracts, and budget encumbrance data. While this is consistent with its stated purpose as a procurement review tool, users should be aware of the high-privilege access requested.
  • [SENSITIVE_FILE_ACCESS]: The 'Self-Evolution Telemetry' section instructs the agent to access and write to the ~/.claude/projects/ directory. Accessing hidden system configuration or project-specific metadata directories is a form of state tracking that could be used for persistence or monitoring across different sessions.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:58 AM
Security Audit — agent-trust-hub — procurement-review