iterative-retrieval
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The core mechanism of the skill involves a loop that ingests content from local files (
file.content) to evaluate relevance and refine further searches. This creates an attack surface for indirect prompt injection, where malicious instructions embedded in a scanned file could manipulate the agent's evaluation scoring or search criteria. - Ingestion points: Content of files gathered during the initial and refined
DISPATCHphases (SKILL.md). - Boundary markers: The described pattern lacks explicit delimiters or instructions to the agent to treat retrieved file content as untrusted data rather than instructions.
- Capability inventory: The pattern utilizes file system retrieval capabilities (
retrieveFiles) and iterative query refinement. - Sanitization: There is no logic provided to sanitize, escape, or filter the content of retrieved files before the agent processes them for evaluation.
- [DATA_EXFILTRATION]: The skill's documentation explicitly references the sensitive local path
~/.claude/agents/in the "Related" section. While this is presented as a reference for where agents are defined, mentioning internal configuration directories can expose sensitive system architecture or prompt templates to the agent's context.
Audit Metadata