project-drift
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8) due to the processing of session transcripts that contain untrusted content. Ingestion points: The skill reads transcript files from both project-local directories and user home folders (e.g.,
~/.codex/sessions) viaproject_drift/transcript_extract.py. Boundary markers: Prompt templates inproject_drift/prompt.pyuse structural markers likeCleaned evidence JSON:but do not provide explicit instructions for the model to ignore potential control sequences within the evidence. Capability inventory: The skill possesses the ability to send data to external endpoints usinghttpxand execute local scripts viasubprocess. Sanitization: Whileproject_drift/utils.pyprovides redaction for certain tags, it does not sanitize the transcript text to prevent the LLM from following instructions embedded in the logs. - [DATA_EXFILTRATION]: The skill reads project documentation (
PROJECT_KNOWLEDGE.md) and session transcripts, then transmits this data to a remote LLM endpoint. Although the target URL is user-configurable via environment variables, this pattern involves sending sensitive project context and development history to an external service.
Audit Metadata