roast-me
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and analyzes user-provided chat transcripts from local storage, creating a potential surface where malicious instructions embedded in past chat logs could influence the agent during the analysis phase.
- Ingestion points: Chat history is retrieved from local directories including
~/.claude/projects/,~/.codex/sessions/, and~/.gemini/tmp/via specialized adapter scripts. - Boundary markers: Transcript data is serialized into structured JSON format by the
extract_prompts.pytool before being passed to LLM subagents for analysis. - Capability inventory: The skill reads local interaction logs, executes its own bundled Python scripts, writes to a local history file (
~/.roast-me-history.json), and outputs markdown results. It has no network capabilities or external dependencies. - Sanitization: The extraction logic enforces character limits on prompt text (1500 characters), error messages (500 characters), and context blocks to mitigate the impact of large or malformed injection payloads.
Audit Metadata