skills/4444j99/a-i--skills/premortem/Gen Agent Trust Hub

premortem

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from various workspace files without explicit sanitization or boundary markers.
  • Ingestion points: Reads CLAUDE.md, the memory/ folder, and general project files via Glob and Read operations.
  • Boundary markers: None identified; the skill does not use specific delimiters to isolate external file content within its prompts.
  • Capability inventory: Performs file system reads, writes HTML and Markdown files to the workspace, and spawns parallel sub-agents for analysis.
  • Sanitization: No sanitization or validation of the ingested content is mentioned before it is processed or rendered.
  • [DYNAMIC_EXECUTION]: The skill generates an HTML report (premortem-report-[timestamp].html) based on aggregated workspace data and opens it for the user. If the ingested data contains malicious HTML or script tags, this could lead to execution in the user's browser context.
  • [DATA_EXFILTRATION]: Accesses sensitive platform-specific files including the memory/ directory and CLAUDE.md which may contain business logic, preferences, and past decision history. While no external network exfiltration was detected, the access to these paths represents a data exposure surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:53 PM
Security Audit — agent-trust-hub — premortem