retro

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface due to its ingestion of untrusted session data.\n
  • Ingestion points: The skill reads primary source materials from local session logs as specified in SKILL.md (Step 2).\n
  • Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands within the logs, allowing potential instructions inside logs to influence the agent.\n
  • Capability inventory: The skill is capable of reading local filesystem logs and invoking other tools like writing-for-agents.\n
  • Sanitization: The instructions do not define any sanitization, filtering, or validation steps for the content retrieved from logs.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 08:53 AM
Security Audit — agent-trust-hub — retro