post-mortem

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external inputs such as 'customer signals' and 'actual outcomes' to generate its retrospective reports. This surface could be exploited if malicious instructions are embedded within those signals.
  • Ingestion points: Reads decision records, execution plans, and customer signals (SKILL.md).
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the ingested signals.
  • Capability inventory: The skill possesses the capability to write markdown records to the local filesystem at ~/.claude/postmortems/ (SKILL.md).
  • Sanitization: There is no evidence of data validation or sanitization for the signals processed during the post-mortem phase.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 01:21 AM
Security Audit — agent-trust-hub — post-mortem