init-context

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill extracts information from untrusted sources within the project repository, including pull request bodies, issue discussions, and source code comments, to generate persistent documentation and glossary entries. This ingestion process is susceptible to indirect prompt injection, where malicious instructions embedded in the project's history could be parsed and executed by the agent during initialization.
  • Ingestion points: As detailed in references/MINING.md and SKILL.md (Step 4), the skill reads data from pull request bodies, issue threads, code files, and git commit history.
  • Boundary markers: The instructions lack explicit requirements for using delimiters or specialized prompts to distinguish between metadata and potential instructions embedded in the mined artifacts.
  • Capability inventory: The skill possesses the capability to write and modify repository files, specifically docs/adr/CONVENTIONS.md, NORTH_STAR.md, CONTEXT.md, and project context files like CLAUDE.md or AGENTS.md (SKILL.md, Steps 2, 3, 5).
  • Sanitization: There is no mention of sanitizing or validating the extracted rationale or vocabulary before it is written into the repository surfaces.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 11:15 AM
Security Audit — agent-trust-hub — init-context