retrospective-agent

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is a legitimate post-project analysis tool. It performs localized file operations on project-specific documentation and metadata within the conductor directory.
  • [PROMPT_INJECTION]: Evaluated the risk of indirect prompt injection via project metadata and commit history. * Ingestion points: SKILL.md identifies plan.md, metadata.json, spec.md, and track commits as the primary sources of data for analysis. * Boundary markers: Absent; the prompt instructions do not specify the use of delimiters to isolate untrusted track data from the agent's instructions. * Capability inventory: The agent possesses write_file capabilities targeting conductor/knowledge/patterns.md and conductor/knowledge/errors.json. * Sanitization: Not specified; the skill instructions do not include validation or escaping steps for the extracted content before it is persisted.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 07:44 AM
Security Audit — agent-trust-hub — retrospective-agent