iterative-retrieval

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The core mechanism of the skill involves a loop that ingests content from local files (file.content) to evaluate relevance and refine further searches. This creates an attack surface for indirect prompt injection, where malicious instructions embedded in a scanned file could manipulate the agent's evaluation scoring or search criteria.
  • Ingestion points: Content of files gathered during the initial and refined DISPATCH phases (SKILL.md).
  • Boundary markers: The described pattern lacks explicit delimiters or instructions to the agent to treat retrieved file content as untrusted data rather than instructions.
  • Capability inventory: The pattern utilizes file system retrieval capabilities (retrieveFiles) and iterative query refinement.
  • Sanitization: There is no logic provided to sanitize, escape, or filter the content of retrieved files before the agent processes them for evaluation.
  • [DATA_EXFILTRATION]: The skill's documentation explicitly references the sensitive local path ~/.claude/agents/ in the "Related" section. While this is presented as a reference for where agents are defined, mentioning internal configuration directories can expose sensitive system architecture or prompt templates to the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:38 AM
Security Audit — agent-trust-hub — iterative-retrieval