compact

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill extracts information from the current conversation—including user-stated plans and unstructured notes—and stores it verbatim using the core_memory tool. This content is re-introduced into the agent's context during session recovery, creating a potential vector where instructions embedded in previous session data could influence future actions.\n
  • Ingestion points: Conversation history, including user messages and session_manager tool outputs defined in the execution flow of SKILL.md.\n
  • Boundary markers: The skill uses Markdown headers (e.g., ## Objective) to structure the data but lacks explicit instructions to ignore or sanitize embedded commands within the recovered blocks.\n
  • Capability inventory: The skill has access to mcp__ccw-tools__core_memory (write access to persistent memory) and mcp__ccw-tools__session_manager (read access to session state).\n
  • Sanitization: No validation, escaping, or filtering is applied to the extracted text before it is imported into core memory.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:20 PM