wachi-compound
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted user data concerning project outcomes and store it in persistent markdown files, creating a potential indirect prompt injection surface. * Ingestion points: User-provided descriptions of product runs, decisions, and build results are captured in Phase 0 and Phase 1. * Boundary markers: The instructions do not define specific delimiters or instructions to prevent the agent from interpreting embedded commands within the captured learning data. * Capability inventory: The skill possesses the capability to write and modify markdown files within the team's data repositories (Wachi Brain, Engram). * Sanitization: The skill lacks explicit sanitization or validation steps to filter potential injection patterns from the user-supplied summaries before they are documented.
Audit Metadata