retain

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external content, specifically call transcripts and client feedback, creating a surface for potential instruction injection.
  • Ingestion points: Meeting transcripts from Fathom (referenced in references/qbr.md) and client communications from WhatsApp or Gmail (referenced in references/check-in.md).
  • Boundary markers: There are no documented boundary markers or "ignore previous instructions" warnings applied when the agent processes external transcript data.
  • Capability inventory: The agent possesses powerful capabilities including bash, run_command, and file manipulation tools (write_to_file, replace_file_content) as defined in agents/openai.yaml.
  • Sanitization: The skill lacks explicit sanitization or validation logic for external content before it is used to summarize priorities or log business decisions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:22 PM
Security Audit — agent-trust-hub — retain