context-manager
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest untrusted repository content to generate instructions that the AI agent treats as authoritative guidance.
- Ingestion points: In
SKILL.md, Steps 1, 2, and 3 explicitly instruct the agent to read existing files such asAGENTS.md,.cursorrules,.windsurfrules,README.md, workspace manifests, and CI workflows to derive project rules. - Boundary markers: Absent. The skill instructions do not specify any delimiters or warnings to the agent to ignore instructions embedded within the ingested data. In fact, Step 4 explicitly defines existing
AGENTS.mdfiles as a "source of truth." - Capability inventory: The skill has the capability to write files to the local filesystem (
CLAUDE.md). These files are automatically loaded by the AI agent at the start of every session, effectively allowing external data to persist as system-level instructions. - Sanitization: Absent. While Step 5 includes a utility-based filter to keep the file concise, there is no security-focused sanitization or validation of the content being synthesized from the repository.
Audit Metadata