compact
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill extracts information from the current conversation—including user-stated plans and unstructured notes—and stores it verbatim using the
core_memorytool. This content is re-introduced into the agent's context during session recovery, creating a potential vector where instructions embedded in previous session data could influence future actions.\n - Ingestion points: Conversation history, including user messages and
session_managertool outputs defined in the execution flow of SKILL.md.\n - Boundary markers: The skill uses Markdown headers (e.g.,
## Objective) to structure the data but lacks explicit instructions to ignore or sanitize embedded commands within the recovered blocks.\n - Capability inventory: The skill has access to
mcp__ccw-tools__core_memory(write access to persistent memory) andmcp__ccw-tools__session_manager(read access to session state).\n - Sanitization: No validation, escaping, or filtering is applied to the extracted text before it is imported into core memory.
Audit Metadata