medium-strategy
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a local shell script
scripts/verify.shused for structural linting of decision records. The script is network-free and performs only read-only validation using standard utilities likegrepandsed. - [INDIRECT_PROMPT_INJECTION]: The skill reads from a local wiki to inform its recommendations, creating an attack surface for indirect prompt injection if history files are modified by external actors.
- Ingestion points: Reads accumulated learnings and decision logs from
02-DOCS/wiki/medium/(SKILL.md §1). - Boundary markers: Absent; the skill does not use specific delimiters or instructions to ignore potential injections within the wiki records.
- Capability inventory: Ability to write decision records to the file system and provide strategic recommendations to the user.
- Sanitization: Absent; the skill does not sanitize or validate the content of the wiki files beyond basic structural checks in
scripts/verify.sh.
Audit Metadata