recall
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill aggregates data from multiple potentially untrusted sources to create a summary brief, creating a surface for indirect prompt injection.
- Ingestion points: The skill reads local chat transcripts from
~/.cursor/projects/and searches external 'shared records' including source control, issue trackers, and chat channels via the 'why' skill. - Boundary markers: There are no explicit instructions or delimiters used to separate user-provided historical data from agent instructions, which could lead to the agent inadvertently following instructions embedded in the logs.
- Capability inventory: The skill has access to shell commands (
ls,grep,git,gh) and the ability to spawn subagents to process data. - Sanitization: The instructions recommend sanitizing private context for final output but do not specify sanitization or validation for the data being ingested.
- [COMMAND_EXECUTION]: The skill uses several system-level commands to gather environment and history metadata.
- Evidence: Executes
ls -tto sort files by modification time,grepto scan chat transcripts for topics, andgitandghto inspect repository branches and pull request status.
Audit Metadata