learn
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is designed to ingest 'session learnings' and persist them into
AGENTS.mdandLESSONS.mdfiles. - Ingestion points: Session history, including outputs from tools and content of files read during task execution (e.g.,
SKILL.mdfiles mentioned in evals). - Boundary markers: No specific delimiters or instructions to ignore embedded commands are specified for the 'distilled notes'.
- Capability inventory: The skill utilizes file-writing capabilities to the root directory and project subdirectories.
- Sanitization: No explicit sanitization or validation of the extracted insights is mentioned before they are persisted.
- [DATA_EXPOSURE]: The instructions reference
agents-docs/ENVIRONMENT_VARIABLES.md. While this points to a potentially sensitive file path, its use is documented for legitimate configuration management purposes rather than unauthorized access or exfiltration.
Audit Metadata