capture-progress
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user conversations to update project artifacts such as
AGENTS.md,README, and ADRs. This ingestion of potentially untrusted chat data creates a surface where malicious instructions could be saved into durable files used by other agents. - Ingestion points: Conversation history and discussion fragments (SKILL.md).
- Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions for the captured content.
- Capability inventory: File system writes, git commits, and execution of local verification tools (SKILL.md).
- Sanitization: While the agent is instructed to 'sharpen the language' and 'remove filler,' there is no explicit security sanitization to filter out prompt injection payloads from being recorded.
- [COMMAND_EXECUTION]: The workflow requires the agent to execute shell-level commands for verification and repository maintenance.
- Evidence: The skill directs the agent to 'run the repo-local checks (lat check, tests, etc.)' and perform a 'git commit' when tracked files are modified (SKILL.md).
Audit Metadata