long-agent

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill architecture creates a surface for indirect prompt injection by processing untrusted data from the local environment.
  • Ingestion points: The skill reads data from the project's src/ directory and from session log files stored in ~/.claude/sessions/.
  • Boundary markers: The skill lacks robust delimiters or boundary markers when interpolating file content into prompts for the gemini command.
  • Capability inventory: The skill enables the agent to perform file system operations (create/read/append) and execute shell commands such as git, grep, and tail.
  • Sanitization: Content read from the environment is used directly in LLM prompts without sanitization or validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 08:25 PM
Security Audit — agent-trust-hub — long-agent