reflect
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes untrusted external data, including project notes, session artifacts, and logs, to generate suggestions for configuration and prompt changes. Maliciously crafted content in these sources could potentially influence the agent to recommend insecure settings or behaviors.
- Ingestion points: Processes project-local guidance, notes, checkpoints, and session logs as defined in the 'Evidence Sources' section of SKILL.md.
- Capability inventory: Has the ability to suggest and, upon user approval, write modifications to skills, custom agents, orchestrator prompts, and configuration files.
- Boundary markers: Implements a confirmation step ('ask before changing') and a 'Core Contract' emphasizing conservative, evidence-driven behavior.
- Sanitization: No specific technical sanitization of log/note content is described beyond the agent's internal reasoning and user review.
Audit Metadata