retro
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external, potentially untrusted data sources including session records, git diffs, test outputs, and issue reports to generate improvements for agent behavior.
- Ingestion points: Data enters the agent's context through session records, git diffs, test outputs, and related issues as described in the 'Collect Evidence' step of SKILL.md.
- Boundary markers: The instructions do not specify explicit delimiters or 'ignore embedded instructions' warnings when processing this external data.
- Capability inventory: If the user explicitly requests implementation of improvements, the skill instructions authorize the agent to modify automatic checks, review documentation, and system instructions (SKILL.md).
- Sanitization: There are no explicit instructions for the agent to sanitize or filter potentially malicious instructions embedded within the logs or diffs it analyzes.
Audit Metadata