iterative-retrieval

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection vulnerability surface. The skill defines a loop where the agent reads and evaluates the contents of codebase files (file.content) to determine relevance and identify missing context. If an attacker places malicious instructions in comments or documentation within the analyzed files, they could potentially influence the agent's logic or future search queries.
  • Ingestion points: Arbitrary codebase files identified by the agent during exploration, such as those in src/ or lib/ directories.
  • Boundary markers: The instructions lack the use of delimiters or specific directives to prevent the agent from following instructions found within the retrieved data.
  • Capability inventory: The skill logic involves file reading and contextual reasoning. While no exfiltration or execution tools are defined in the snippets, the pattern is intended for use in agents that typically possess file and terminal access.
  • Sanitization: There is no evidence of sanitization, validation, or filtering of the retrieved content before it is processed by the agent's reasoning loop.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 03:42 AM
Security Audit — agent-trust-hub — iterative-retrieval