soc2
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data from an entire project directory without using boundary markers or 'ignore' instructions. Malicious content hidden within the audited files could potentially manipulate the assessment verdict or instructions given to the agent.\n
- Ingestion points: The entire project directory or a path specified in $ARGUMENTS.\n
- Boundary markers: Absent; project content is processed as part of the primary task context.\n
- Capability inventory: Filesystem read access, file write access (telemetry), and generation of complex Markdown reports.\n
- Sanitization: Absent.\n- [COMMAND_EXECUTION]: The 'SELF-EVOLUTION TELEMETRY' section instructs the agent to perform file system checks and write operations to a specific hidden directory (~/.claude/projects/). This automated behavior persists execution metadata across sessions in a location outside the immediate project scope.
Audit Metadata