property-roi

Warn

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill implements a persistence mechanism by writing execution metadata to the hidden directory ~/.claude/projects/. This involves modifying internal application state files outside of the intended project documentation scope.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection through its analysis of untrusted codebase data.
  • Ingestion points: Target codebase files, package manifests, and financial models (SKILL.md).
  • Boundary markers: None identified; the skill lacks delimiters or safety warnings for processing external content.
  • Capability inventory: Extensive file read access, writing to the docs/ directory, and writing to hidden configuration paths (SKILL.md).
  • Sanitization: None identified; content is processed without validation or escaping.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 23, 2026, 10:57 AM
Security Audit — agent-trust-hub — property-roi