artifact-resurfacing
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data by reading repository documentation files to extract and validate file citations. This creates a surface where malicious instructions could theoretically be embedded in the audited files.
- Ingestion points: Target files such as
CLAUDE.mdandMEMORY.mdare parsed by thescripts/audit-citations.shscript to identify path-like tokens. - Boundary markers: The skill implements a robust 'propose-not-apply' policy, explicitly documented in
SKILL.mdandreferences/constitutional-doc-policy.md, which ensures the AI agent only generates proposals and requires explicit user consent before any edits are applied. - Capability inventory: Filesystem operations are limited to read-only discovery using standard tools (
find,grep). Modification capabilities are restricted to generating unified diffs for review and appending to a local log file. - Sanitization: The
scripts/audit-citations.shscript includes logic to escape special characters in its JSONL output, mitigating the risk of downstream parsing vulnerabilities. - [SAFE]: Technical analysis of the provided shell and Python scripts confirms they perform only the advertised tasks of path verification and diff generation. No evidence of data exfiltration, credential exposure, obfuscation, or persistence mechanisms was detected. The skill's operations are transparent and confined to the local development environment.
Audit Metadata