setup-learnings-inbox

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Uses git rev-parse --show-toplevel to identify the repository's root directory during the setup process.
  • [PROMPT_INJECTION]: Modifies repository instruction files (CLAUDE.md, AGENTS.md) to include persistent directives for the agent. This modification is the core purpose of the skill to enable automated knowledge capture.
  • [PROMPT_INJECTION]: Establishes an Indirect Prompt Injection surface where the agent reads context from a repository file (docs/learnings/LEARNINGS.md) that could be modified by other contributors.
  • Ingestion points: The agent is instructed via updated router files to read docs/learnings/LEARNINGS.md before starting tasks.
  • Boundary markers: No specific delimiters are used to separate the external 'learnings' content from the agent's primary instructions.
  • Capability inventory: The skill can execute shell commands (git) and modify repository-level instruction files.
  • Sanitization: There is no mechanism to sanitize or validate the content of the learnings files before the agent processes them.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 12:56 PM
Security Audit — agent-trust-hub — setup-learnings-inbox