periodic-retreat
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data during its retrospective and debt purge phases, creating a vulnerability where malicious content in processed files could influence agent behavior.
- Ingestion points: Ingests the previous quarter's roadmaps, commit history, and general project files as specified in Step 1 of the SKILL.md procedure.
- Boundary markers: Absent. There are no instructions to the agent to treat audited content as data rather than instructions or to use specific delimiters.
- Capability inventory: The agent is granted
bash,view_file,write_to_file, andreplace_file_contenttools (defined in agents/openai.yaml). - Sanitization: Absent. The procedure does not include steps for validating, escaping, or filtering the content of the audited files before they influence 'Debt Purge' decisions.
- [EXTERNAL_DOWNLOADS]: Provides installation instructions to fetch the skill from the author's GitHub repository (harshsinghmp/muse-skills) using the platform's standard installer.
- [COMMAND_EXECUTION]: The agent uses a
bashtool to perform technical audits and manage the 'Debt Purge' phase, which involves identified file removals and subsystem consolidations.
Audit Metadata