compact-prep
Pass
Audited by Gen Agent Trust Hub on Jul 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted data which presents an indirect prompt injection surface.
- Ingestion points: Reading active plan files and accepting a
[復旧メモ]argument as specified in SKILL.md. - Boundary markers: None identified; the skill does not wrap ingested content in delimiters or provide instructions to the agent to ignore embedded commands.
- Capability inventory: The skill uses
Bash(restricted to specific local scripts and utilities) andWritetools as listed in the frontmatter. - Sanitization: No input validation or sanitization is performed on the data before it is recorded into state files.
Audit Metadata