init-context
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill extracts information from untrusted sources within the project repository, including pull request bodies, issue discussions, and source code comments, to generate persistent documentation and glossary entries. This ingestion process is susceptible to indirect prompt injection, where malicious instructions embedded in the project's history could be parsed and executed by the agent during initialization.
- Ingestion points: As detailed in
references/MINING.mdandSKILL.md(Step 4), the skill reads data from pull request bodies, issue threads, code files, and git commit history. - Boundary markers: The instructions lack explicit requirements for using delimiters or specialized prompts to distinguish between metadata and potential instructions embedded in the mined artifacts.
- Capability inventory: The skill possesses the capability to write and modify repository files, specifically
docs/adr/CONVENTIONS.md,NORTH_STAR.md,CONTEXT.md, and project context files likeCLAUDE.mdorAGENTS.md(SKILL.md, Steps 2, 3, 5). - Sanitization: There is no mention of sanitizing or validating the extracted rationale or vocabulary before it is written into the repository surfaces.
Audit Metadata