cw-save

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes and updates project configuration files based on context, which creates a surface where embedded instructions could influence behavior.
  • Ingestion points: The skill reads references/context-contract.md and other project files in the workspace.
  • Boundary markers: No specific boundary markers or delimiters are used to isolate content within the ingested files.
  • Capability inventory: The skill possesses file-write capabilities to modify project documentation like VOICE.md and STYLE.md.
  • Sanitization: The skill lacks explicit sanitization for ingested content, although it requires user confirmation for any rules it infers.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 06:43 PM
Security Audit — agent-trust-hub — cw-save