periodic-retreat

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data during its retrospective and debt purge phases, creating a vulnerability where malicious content in processed files could influence agent behavior.
  • Ingestion points: Ingests the previous quarter's roadmaps, commit history, and general project files as specified in Step 1 of the SKILL.md procedure.
  • Boundary markers: Absent. There are no instructions to the agent to treat audited content as data rather than instructions or to use specific delimiters.
  • Capability inventory: The agent is granted bash, view_file, write_to_file, and replace_file_content tools (defined in agents/openai.yaml).
  • Sanitization: Absent. The procedure does not include steps for validating, escaping, or filtering the content of the audited files before they influence 'Debt Purge' decisions.
  • [EXTERNAL_DOWNLOADS]: Provides installation instructions to fetch the skill from the author's GitHub repository (harshsinghmp/muse-skills) using the platform's standard installer.
  • [COMMAND_EXECUTION]: The agent uses a bash tool to perform technical audits and manage the 'Debt Purge' phase, which involves identified file removals and subsystem consolidations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:27 PM
Security Audit — agent-trust-hub — periodic-retreat