risk-simulation
Warn
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: MEDIUMPROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains instructions to override standard interactive behavior by commanding the agent to "Do NOT ask the user questions" and to "Analyze and act" autonomously, which reduces human oversight and bypasses confirmation prompts.- [DATA_EXFILTRATION]: The skill performs discovery on sensitive data types and file paths, including military operational planning documents such as "CONOPs, OPLANs, OPORDs, campaign plans" and organizational risk registers.- [DATA_EXFILTRATION]: The skill accesses the user's home directory at
~/.claude/projects/to search for project metadata and append execution logs toskill-telemetry.md, which constitutes a side-channel for data persistence and local information gathering.- [COMMAND_EXECUTION]: The instructions direct the agent to "Build and execute probabilistic risk models" and "Configure iteration count", which implies the dynamic generation and execution of code (e.g., Python scripts) to perform complex simulations based on ingested project data.- [PROMPT_INJECTION]: The skill contains a vulnerability surface for indirect prompt injection as it ingests untrusted data from risk registers and planning documents without boundary markers or sanitization, while possessing capabilities for file writing and code execution.
Audit Metadata