tax-compliance
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill attempts to access and write to the hidden home directory path
~/.claude/projects/to store execution metadata inskill-telemetry.md. Accessing hidden application configuration or system directories is a risk factor for data exposure. - [PROMPT_INJECTION]: The instructions contain the directive 'Do NOT ask the user questions', which explicitly overrides the default conversational and safety-seeking behavior of the AI agent.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting untrusted data from
$ARGUMENTSand external tax systems (ERPs like SAP/Oracle, tax engines) without implementing boundary markers or sanitization. - Ingestion points: External tax engines, ERP modules, and the
$ARGUMENTSvariable (SKILL.md). - Boundary markers: None provided to isolate untrusted data from instructions.
- Capability inventory: File writes to
docs/tax-compliance-analysis.mdand~/.claude/projects/skill-telemetry.md. - Sanitization: None detected for processed external data.
Audit Metadata