pk-reflect

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes the entire conversation history, which consists of untrusted user input, to extract 'candidates' for other internal tools such as 'pk-capture' and 'pk-analyze'.\n
  • Ingestion points: Full session conversation history (SKILL.md).\n
  • Boundary markers: No explicit markers or instructions to ignore embedded commands are used during the conversation scanning or interview processes.\n
  • Capability inventory: The skill is capable of invoking 'pk-capture' to modify an inbox/log and 'pk-analyze' to process metrics and trends.\n
  • Sanitization: Content is filtered for relevance ('actionable' lessons), but there is no technical sanitization or escaping of the user-provided strings before they are handed over to secondary processes.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 01:17 PM
Security Audit — agent-trust-hub — pk-reflect