retro
Warn
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill accesses sensitive information by reading and summarizing session transcripts stored in the user's home directory.
- Obfuscation: The helper script
retro_extract.pyobfuscates the path to application logs using string concatenation(".cl" "aude")to construct the directory name. This is often used to evade simple static analysis tools that monitor access to specific application folders. - Sensitive File Access: The skill accesses transcript files in
~/.claude/projects/, which contain full history of user conversations, tool usage logs, and environment metadata. - [PROMPT_INJECTION]: The skill presents an attack surface for Indirect Prompt Injection because it processes untrusted session data and possesses the capability to modify local skill and agent files.
- Ingestion points:
retro_extract.pyextracts raw message content and tool outputs from JSONL transcripts for AI processing. - Boundary markers: The script does not implement delimiters or explicit instructions to treat the extracted log data as untrusted, increasing the risk that the AI may follow commands embedded within the logs.
- Capability inventory:
SKILL.mdcontains instructions for the agent to "edit the skill file directly" during its improvement phase. - Sanitization: No validation or sanitization is performed on the data extracted from session logs before it is interpolated into the agent's context.
Audit Metadata