production-scheduling
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The skill is designed to read sensitive system configuration files and data structures from industrial platforms like SAP PP, Oracle Manufacturing, and various MES/ERP systems (SKILL.md, Phase 1). While this is aligned with its stated purpose of auditing, it grants the agent access to proprietary architecture and potentially sensitive configuration data within the manufacturing environment.\n- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests and processes untrusted data from the analyzed codebase and system configurations (SKILL.md, Phase 1.1).\n
- Ingestion points: Project files, system configurations, and manufacturing data models.\n
- Boundary markers: Absent. The instructions do not provide delimiters or warnings to ignore instructions embedded within the analyzed files.\n
- Capability inventory: The skill has file read access (entire project/system) and file write access (report generation and telemetry logging).\n
- Sanitization: No sanitization or validation of the ingested content is performed before processing.\n- [COMMAND_EXECUTION]: The 'Self-Evolution Telemetry' section instructs the agent to search for and write to a hidden directory in the user's home folder (~/.claude/projects/). This represents an automated file system operation outside the immediate project scope, targeting platform-specific metadata stores.
Audit Metadata