cw-save
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes and updates project configuration files based on context, which creates a surface where embedded instructions could influence behavior.
- Ingestion points: The skill reads
references/context-contract.mdand other project files in the workspace. - Boundary markers: No specific boundary markers or delimiters are used to isolate content within the ingested files.
- Capability inventory: The skill possesses file-write capabilities to modify project documentation like
VOICE.mdandSTYLE.md. - Sanitization: The skill lacks explicit sanitization for ingested content, although it requires user confirmation for any rules it infers.
Audit Metadata