context-anchor

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill manages session state by reading and writing local Markdown files within the project's .agents/ directory using standard file operations.
  • [SAFE]: The instructions contain explicit safeguards against data exposure, strictly forbidding the storage of secrets, credentials, or legal client names in the anchor artifacts.
  • [SAFE]: A 'Context Hierarchy & Trust' protocol is implemented to classify external or browser-sourced content as untrusted, directing the agent to prioritize local rules and source code over potentially malicious history.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves ingesting session history and tool outputs, which constitutes a potential attack surface for indirect prompt injection.
  • Ingestion points: Reads active session state and tool outputs to generate anchors in SKILL.md (Step 1) and agents/openai.yaml.
  • Boundary markers: The skill uses markdown formatting for structure but does not implement strict delimiters or escaping for untrusted data processed into the anchor.
  • Capability inventory: The agent is restricted to view_file and write_to_file. It lacks capabilities for network communication, subprocess execution, or privilege escalation.
  • Sanitization: Sanitization is handled via model instructions that mandate verification of untrusted content against source code before action.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:23 PM
Security Audit — agent-trust-hub — context-anchor