recall
Pass
Audited by Gen Agent Trust Hub on Aug 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary function is to summarize historical data from authorized sources. No evidence of malicious intent, credential theft, or unauthorized network activity was found.
- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface due to its core function of ingesting data from external sources like tickets, team discussions, and historical logs.
- Ingestion points:
SKILL.md(Step 3: Mining authorized working history; Step 4: Sweeping the shared record including tickets and documents). - Boundary markers: Absent. There are no instructions to the agent to use specific delimiters or to disregard instructions found within the ingested historical data.
- Capability inventory: The skill utilizes tools for repository state verification, history synthesis, and multi-agent coordination via the
pstackcontract. - Sanitization: Absent. While the skill mentions removing private context, it does not specify sanitization or escaping of the ingested content to prevent instructions in those sources from influencing the agent's behavior.
Audit Metadata