deepwork
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to create and maintain a persistent markdown file under
.slim/deepwork/to store research findings from external agents (like@librarian) and review feedback from others (like@oracle). This content is then used to guide subsequent planning and implementation phases, creating a path for malicious instructions from external sources to influence the agent's logic in future steps.\n - Ingestion points: Research findings, documentation, and external references reconciled from
@librarianare recorded in the task-specific progress file in.slim/deepwork/.\n - Boundary markers: The instructions do not specify the use of clear delimiters or instructions to ignore embedded commands when re-processing the stored research context.\n
- Capability inventory: The skill manages task delegations, writes to local files, and modifies project configuration files such as
.gitignoreand.ignore.\n - Sanitization: There are no explicit requirements for the agent to sanitize, validate, or filter the external findings before incorporating them into the persistent session state.
Audit Metadata