quote-automation

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill is configured to record telemetry data to ~/.claude/projects/skill-telemetry.md. This involves writing execution logs to a hidden folder in the user's home directory, which allows tracking of the agent's usage and performance across different project environments.- [PROMPT_INJECTION]: The skill instructs the agent to act with high autonomy, stating "Do NOT ask the user questions" and "scan the current project". This configuration limits user interaction and can result in the agent automatically following instructions embedded in the codebase being analyzed.- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface. Ingestion points: The agent reads the local codebase and provided arguments. Boundary markers: The instructions do not define clear delimiters or include warnings to ignore instructions found within the analyzed data. Capability inventory: The skill has permissions to read arbitrary files in the project and write to both project-specific documentation and the user's home folder. Sanitization: There is no logic to sanitize or validate the content of the codebase before it is processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:57 AM
Security Audit — agent-trust-hub — quote-automation