recap-validate

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data in the form of RecapPageContent JSON to perform its validation tasks, which presents a surface for indirect instructions.
  • Ingestion points: The content argument or the default file path at apps/recap-web/src/content/active.json.
  • Boundary markers: The instructions do not specify delimiters or explicit instructions to ignore embedded commands within the processed JSON content.
  • Capability inventory: The skill is limited to reading local project files and writing a validation report to the artifacts directory.
  • Sanitization: No explicit sanitization or filtering of the input content is described before the review process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 10:48 AM
Security Audit — agent-trust-hub — recap-validate