context-engine

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and process external codebase data and persistent memory files, which presents a surface for indirect prompt injection.
  • Ingestion points: The context_analyzer.py, context_pruner.py, and memory_indexer.py scripts read source code and documentation from file paths provided to the tools.
  • Boundary markers: Although the skill documentation suggests architectural patterns like 'anchors' to maintain control, the provided scripts do not enforce strict structural delimiters or include instructions to ignore embedded directives in the content they process.
  • Capability inventory: The skill scripts are limited to local file system access (reads and writes) and do not possess network access, privileged execution, or dynamic evaluation capabilities.
  • Sanitization: The scripts utilize tokenization and regex-based pruning but do not include specific sanitization logic to detect or neutralize malicious prompt injection sequences hidden within the ingested text.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:23 AM
Security Audit — agent-trust-hub — context-engine