property-roi
Warn
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill implements a persistence mechanism by writing execution metadata to the hidden directory
~/.claude/projects/. This involves modifying internal application state files outside of the intended project documentation scope. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection through its analysis of untrusted codebase data.
- Ingestion points: Target codebase files, package manifests, and financial models (SKILL.md).
- Boundary markers: None identified; the skill lacks delimiters or safety warnings for processing external content.
- Capability inventory: Extensive file read access, writing to the
docs/directory, and writing to hidden configuration paths (SKILL.md). - Sanitization: None identified; content is processed without validation or escaping.
Audit Metadata