retro
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface due to its ingestion of untrusted session data.\n
- Ingestion points: The skill reads primary source materials from local session logs as specified in
SKILL.md(Step 2).\n - Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands within the logs, allowing potential instructions inside logs to influence the agent.\n
- Capability inventory: The skill is capable of reading local filesystem logs and invoking other tools like
writing-for-agents.\n - Sanitization: The instructions do not define any sanitization, filtering, or validation steps for the content retrieved from logs.
Audit Metadata