skills/cursor/plugins/recall/Gen Agent Trust Hub

recall

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill aggregates data from multiple potentially untrusted sources to create a summary brief, creating a surface for indirect prompt injection.
  • Ingestion points: The skill reads local chat transcripts from ~/.cursor/projects/ and searches external 'shared records' including source control, issue trackers, and chat channels via the 'why' skill.
  • Boundary markers: There are no explicit instructions or delimiters used to separate user-provided historical data from agent instructions, which could lead to the agent inadvertently following instructions embedded in the logs.
  • Capability inventory: The skill has access to shell commands (ls, grep, git, gh) and the ability to spawn subagents to process data.
  • Sanitization: The instructions recommend sanitizing private context for final output but do not specify sanitization or validation for the data being ingested.
  • [COMMAND_EXECUTION]: The skill uses several system-level commands to gather environment and history metadata.
  • Evidence: Executes ls -t to sort files by modification time, grep to scan chat transcripts for topics, and git and gh to inspect repository branches and pull request status.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 06:22 PM
Security Audit — agent-trust-hub — recall