relay
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill reconstructs session state using a "state-source ladder" that reads from local files and git history. \n
- Ingestion points: The agent uses
view_fileto read from.agents/artifacts/HANDOFF.mdand.agents/context/current.md, andbashto parse the output of git commands. \n - Boundary markers: The instructions define a brief summary format but lack explicit delimiters or safety instructions for the ingested text to prevent the agent from following instructions embedded within the state data. \n
- Capability inventory: The agent utilizes the
bash,view_file, andwrite_to_filetools, providing a wide scope of action if the agent is influenced by malicious state. \n - Sanitization: There is no evidence of sanitization or validation performed on the content retrieved from state-source files before identifying the "Next Step". \n- [COMMAND_EXECUTION]: The skill uses the
bashtool to execute repository forensics commands (e.g.,git status,git log,git diff) to identify the current work state. \n- [EXTERNAL_DOWNLOADS]: The documentation references installation vianpxfrom a vendor-owned repository (harshsinghmp/muse-skills).
Audit Metadata