context-resume
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes session data from local Markdown files and is instructed to follow the 'next action' recommendations found within them. This creates an indirect prompt injection surface where malicious content in a session file could potentially influence the agent's behavior. The ingestion point is the 'docs/context-sessions/' directory. The skill lacks explicit sanitization or boundary markers to distinguish between trusted instructions and user-provided session notes, although its capabilities are limited to local file operations and task management.
Audit Metadata