gap-remediate

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from ~/.claude/dream/agent-gaps.log, which contains observations from past user sessions. If an attacker influences a session to produce a specific 'gap' entry, this skill could unintentionally promote that malicious payload into the agent's core behavioral guidelines in AGENTS.md.\n
  • Ingestion points: ~/.claude/dream/agent-gaps.log (SKILL.md).\n
  • Boundary markers: Absent. While the skill advises the agent to sanity-check claims, it does not use structural delimiters or explicit instructions to treat the log content as data rather than instructions.\n
  • Capability inventory: Write, Edit, and Bash allow the skill to modify sensitive configuration files and execute system commands.\n
  • Sanitization: Absent. There is no automated validation or filtering of the content being written to the knowledge surfaces.\n- [COMMAND_EXECUTION]: The skill relies on the Bash tool and interacts with a local semantic vault utility ke (e.g., ke recall-info) to retrieve and verify knowledge. These capabilities provide the agent with the necessary permissions to modify its own configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 08:52 PM
Security Audit — agent-trust-hub — gap-remediate