idk-now
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from the repository and git history to formulate project vision and session goals, creating a surface for indirect instructions.
- Ingestion points: SKILL.md and references/flow.md define a survey process that reads README.md, AGENTS.md, CLAUDE.md, PRODUCT.md, VISION.md, docs/, .productfeeling/, FEELING.md, and git log.
- Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore potentially malicious directions embedded within these project files during the survey phase.
- Capability inventory: While the skill is primarily read-only (using tools like git log and find), it recommends the execution of other high-impact skills (such as fix-it, merge-it, ship-it, and repos) based on the analysis of the untrusted data.
- Sanitization: The instructions do not define any sanitization, escaping, or validation of the ingested file content before it is used to influence the agent's decision-making logic.
Audit Metadata