skills/broomva/skills/premortem/Gen Agent Trust Hub

premortem

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes a data ingestion surface by reading workspace files to inform its analysis.
  • Ingestion points: Specifically targets files like CLAUDE.md, content within the memory/ directory, and user-referenced project files using Glob and Read tools.
  • Boundary markers: The sub-agent prompt template lacks explicit delimiters or instructions to ignore potential commands embedded within the retrieved workspace context.
  • Capability inventory: The agent maintains permissions to read arbitrary workspace files and write generated reports as .html and .md files.
  • Sanitization: The instructions do not describe any mechanisms for filtering or escaping ingested data before it is included in sub-agent prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 03:33 PM
Security Audit — agent-trust-hub — premortem