tax-compliance

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill attempts to access and write to the hidden home directory path ~/.claude/projects/ to store execution metadata in skill-telemetry.md. Accessing hidden application configuration or system directories is a risk factor for data exposure.
  • [PROMPT_INJECTION]: The instructions contain the directive 'Do NOT ask the user questions', which explicitly overrides the default conversational and safety-seeking behavior of the AI agent.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting untrusted data from $ARGUMENTS and external tax systems (ERPs like SAP/Oracle, tax engines) without implementing boundary markers or sanitization.
  • Ingestion points: External tax engines, ERP modules, and the $ARGUMENTS variable (SKILL.md).
  • Boundary markers: None provided to isolate untrusted data from instructions.
  • Capability inventory: File writes to docs/tax-compliance-analysis.md and ~/.claude/projects/skill-telemetry.md.
  • Sanitization: None detected for processed external data.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:57 AM
Security Audit — agent-trust-hub — tax-compliance