underwriting-analysis

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill has an inherent attack surface for indirect prompt injection as it processes untrusted project data and user-supplied arguments.
  • Ingestion points: User-provided $ARGUMENTS and various project configuration files (e.g., requirements.txt, pom.xml, rule engine configs, and rating algorithm files).
  • Boundary markers: The skill does not define explicit delimiters to separate instructions from the data being analyzed.
  • Capability inventory: The skill performs file system reads, directory creation (docs/), and writes analysis reports and telemetry data.
  • Sanitization: No specific sanitization or validation of the ingested data is mentioned prior to processing.
  • [COMMAND_EXECUTION]: The skill instructs the agent to automate the discovery and analysis process, including writing execution metadata to a local hidden directory (~/.claude/projects/). This is a standard mechanism for self-evolution and performance tracking within specific agent platforms and does not involve malicious persistence or unauthorized external communication.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:57 AM
Security Audit — agent-trust-hub — underwriting-analysis