postmortem

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes a workflow for analyzing user-reported incidents and automatically implementing fixes, which introduces a potential attack surface for indirect instructions.\n
  • Ingestion points: User-provided incident descriptions and responses captured during the retrospective process in SKILL.md.\n
  • Boundary markers: The instructions lack explicit delimiters or guidance to distinguish between user-provided data and the agent's internal logic when implementing changes.\n
  • Capability inventory: The skill utilizes Write and Edit tools to modify critical project configuration files such as SKILL.md, rules/*.md, and MEMORY.md.\n
  • Sanitization: No specific validation or filtering steps are defined to sanitize user input before it is used to generate or modify persistent project instructions or rules.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 11:11 PM
Security Audit — agent-trust-hub — postmortem