public-resource-allocation

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill identifies external data sources for ingestion, including survey/feedback data and external APIs (Step 1.3). This represents an indirect prompt injection surface where malicious instructions could be embedded in the data processed by the agent. Ingestion points: Phase 1, Step 1.3. Boundary markers: Absent. Capability inventory: Extensive file read access and local telemetry write access. Sanitization: Absent. Evidence: SKILL.md Phase 1 Step 1.3.\n- [DATA_EXFILTRATION]: The skill implements a telemetry mechanism that writes metadata regarding execution success, bottlenecks, and suggestions to a hidden directory (~/.claude/projects/skill-telemetry.md). While this is a local file append operation used for performance tracking and skill evolution, it represents a persistent write outside the immediate project scope. Evidence: SKILL.md 'SELF-EVOLUTION TELEMETRY' section.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:57 AM
Security Audit — agent-trust-hub — public-resource-allocation