sustainability-metrics

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted data from the analyzed codebase and external integrations, creating a surface for indirect prompt injection. Ingestion points include the entire codebase and configuration files like package.json and requirements.txt. No specific boundary markers or sanitization are defined for the ingested content, though the skill's focus is limited to ESG audit tasks.
  • [DATA_EXFILTRATION]: The skill accesses architectural information, including database schemas and external data provider configurations. This data exposure is required to perform the materiality and metric accuracy audits specified in the skill's instructions.
  • [COMMAND_EXECUTION]: The skill records performance telemetry by appending execution metadata to ~/.claude/projects/skill-telemetry.md. This involves localized file system operations within the agent's project environment for logging and self-improvement purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:58 AM
Security Audit — agent-trust-hub — sustainability-metrics