skills/andabove/skills/reflect/Gen Agent Trust Hub

reflect

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes session transcripts, which are inherently untrusted and could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: The transcript content is ingested by the reviewer agents defined in the references directory and synthesized by the synthesizer agent.
  • Boundary markers: The prompt templates include strong, explicit instructions to treat the transcript as untrusted data and to ignore any embedded directives or instructions within it.
  • Capability inventory: The skill possesses the capability to modify repository files (specifically SKILL.md files) and interact with external systems via MCP tools such as ticket trackers or observability tools.
  • Sanitization: The primary defense is a mandatory user-approval step where the agent must present all proposed changes to the user and wait for explicit confirmation before applying them. Additionally, the analysis is distributed across multiple subagents to ensure consistency and reduce the impact of any single successful injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 06:23 PM
Security Audit — agent-trust-hub — reflect