strategic-compaction

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute shell commands (find, cat, wc) to audit session logs and usage metrics within the .forgewright directory.
  • [COMMAND_EXECUTION]: The skill executes a local shell script (./scripts/memory-hygiene.sh) to perform maintenance tasks such as pruning duplicate queries and compressing history.
  • [COMMAND_EXECUTION]: A Python script is used to simulate the offloading of large data payloads by writing content to local storage files within .forgewright/offload/.
  • [PROMPT_INJECTION]: The skill monitors user messages and conversation history to detect logical breakpoints and milestone words, which creates an indirect prompt injection surface.
  • Ingestion points: The skill ingests the userMessage and the last 10 turns of conversation history via detection logic in SKILL.md.
  • Boundary markers: No explicit delimiters are defined to separate user content from the logic used to evaluate trigger words.
  • Capability inventory: The skill has the capability to execute local scripts, search the filesystem, and write files to local project directories.
  • Sanitization: No sanitization or escaping is performed on the message content before it is evaluated against trigger word lists.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 08:30 AM
Security Audit — agent-trust-hub — strategic-compaction