self-review
Pass
Audited by Gen Agent Trust Hub on May 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill enables the assistant to ingest untrusted data from historical conversations to guide behavioral changes.
- Ingestion Points: The skill processes current and historical chat sessions in Step 1 and Step 2 of the 'Historical Mode' (SKILL.md).
- Boundary Markers: Absent. The instructions lack delimiters or constraints to prevent the agent from being influenced by instructions found within the logs it is analyzing.
- Capability Inventory: The agent has the capability to propose and implement (with user consent) modifications to sensitive control surfaces such as
CLAUDE.md(global instructions), memory, and path-scoped rules (SKILL.md). - Sanitization: No sanitization or verification mechanism is described for the ingested conversation data.
Audit Metadata