context-manager

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest untrusted repository content to generate instructions that the AI agent treats as authoritative guidance.
  • Ingestion points: In SKILL.md, Steps 1, 2, and 3 explicitly instruct the agent to read existing files such as AGENTS.md, .cursorrules, .windsurfrules, README.md, workspace manifests, and CI workflows to derive project rules.
  • Boundary markers: Absent. The skill instructions do not specify any delimiters or warnings to the agent to ignore instructions embedded within the ingested data. In fact, Step 4 explicitly defines existing AGENTS.md files as a "source of truth."
  • Capability inventory: The skill has the capability to write files to the local filesystem (CLAUDE.md). These files are automatically loaded by the AI agent at the start of every session, effectively allowing external data to persist as system-level instructions.
  • Sanitization: Absent. While Step 5 includes a utility-based filter to keep the file concise, there is no security-focused sanitization or validation of the content being synthesized from the repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 06:51 PM
Security Audit — agent-trust-hub — context-manager