project-drift

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8) due to the processing of session transcripts that contain untrusted content. Ingestion points: The skill reads transcript files from both project-local directories and user home folders (e.g., ~/.codex/sessions) via project_drift/transcript_extract.py. Boundary markers: Prompt templates in project_drift/prompt.py use structural markers like Cleaned evidence JSON: but do not provide explicit instructions for the model to ignore potential control sequences within the evidence. Capability inventory: The skill possesses the ability to send data to external endpoints using httpx and execute local scripts via subprocess. Sanitization: While project_drift/utils.py provides redaction for certain tags, it does not sanitize the transcript text to prevent the LLM from following instructions embedded in the logs.
  • [DATA_EXFILTRATION]: The skill reads project documentation (PROJECT_KNOWLEDGE.md) and session transcripts, then transmits this data to a remote LLM endpoint. Although the target URL is user-configurable via environment variables, this pattern involves sending sensitive project context and development history to an external service.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — project-drift