iterative-retrieval

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a methodology for agents to retrieve and process codebase files as context. This ingestion of external, potentially untrusted data creates a vulnerability surface where instructions embedded in the source code could influence agent behavior.
  • Ingestion points: External codebase files retrieved during the DISPATCH phase as described in SKILL.md.
  • Boundary markers: Absent. The pseudocode examples do not demonstrate the use of delimiters or specific instructions to the agent to ignore embedded commands in retrieved content.
  • Capability inventory: The pattern is designed for agents that typically possess capabilities such as file system access and tool execution.
  • Sanitization: Absent. The logic focuses on relevance scoring and gap identification rather than sanitization or safety filtering of retrieved data.
  • [NO_CODE]: The skill is comprised solely of markdown documentation and illustrative pseudocode. It does not include any executable scripts, automated tasks, or platform-specific command injections.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:39 PM
Security Audit — agent-trust-hub — iterative-retrieval