long-agent
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill architecture creates a surface for indirect prompt injection by processing untrusted data from the local environment.
- Ingestion points: The skill reads data from the project's
src/directory and from session log files stored in~/.claude/sessions/. - Boundary markers: The skill lacks robust delimiters or boundary markers when interpolating file content into prompts for the
geminicommand. - Capability inventory: The skill enables the agent to perform file system operations (create/read/append) and execute shell commands such as
git,grep, andtail. - Sanitization: Content read from the environment is used directly in LLM prompts without sanitization or validation.
Audit Metadata