iterative-retrieval
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes a methodology for agents to retrieve and process codebase files as context. This ingestion of external, potentially untrusted data creates a vulnerability surface where instructions embedded in the source code could influence agent behavior.
- Ingestion points: External codebase files retrieved during the DISPATCH phase as described in SKILL.md.
- Boundary markers: Absent. The pseudocode examples do not demonstrate the use of delimiters or specific instructions to the agent to ignore embedded commands in retrieved content.
- Capability inventory: The pattern is designed for agents that typically possess capabilities such as file system access and tool execution.
- Sanitization: Absent. The logic focuses on relevance scoring and gap identification rather than sanitization or safety filtering of retrieved data.
- [NO_CODE]: The skill is comprised solely of markdown documentation and illustrative pseudocode. It does not include any executable scripts, automated tasks, or platform-specific command injections.
Audit Metadata