regulatory-submissions

Warn

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions in the 'SELF-EVOLUTION TELEMETRY' section direct the agent to locate an internal project memory directory at '/.claude/projects/' and append execution metadata to 'skill-telemetry.md'. Writing to hidden application-specific state directories outside the immediate project scope is a persistence mechanism that tracks execution across sessions.\n- [DATA_EXFILTRATION]: The skill attempts to access the agent's internal metadata by reading from '/.claude/projects/'. Since this directory contains project-specific memory and state information for the agent itself, unauthorized access poses a data exposure risk.\n- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) because it ingests untrusted data from multiple sources (XML schemas, eCTD backbone files, PDF documents, and integration configs) to generate reports. Evidence chain: (1) Ingestion points: XML/PDF files, *.stf metadata, and ESG/CESP configs. (2) Boundary markers: Absent in the prompt. (3) Capability inventory: File system write access to 'docs/' and agent-internal telemetry paths. (4) Sanitization: No sanitization or validation of the content of these external files is specified before processing.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 23, 2026, 10:57 AM
Security Audit — agent-trust-hub — regulatory-submissions