iterative-retrieval
Pass
Audited by Gen Agent Trust Hub on Apr 6, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill facilitates a workflow where the agent ingests untrusted codebase data, creating a surface for executing instructions hidden in files. * Ingestion points: Content is ingested via the
retrieveFilesmechanism described inSKILL.md. * Boundary markers: The suggested prompts lack delimiters or safety instructions to isolate retrieved content from agent instructions. * Capability inventory: The skill is intended for agents with file system access and tool execution capabilities. * Sanitization: No sanitization steps are provided for the retrieved content. - [NO_CODE]: The skill consists entirely of documentation and pseudo-code examples and does not include executable scripts.
Audit Metadata