wachi-compound

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted user data concerning project outcomes and store it in persistent markdown files, creating a potential indirect prompt injection surface. * Ingestion points: User-provided descriptions of product runs, decisions, and build results are captured in Phase 0 and Phase 1. * Boundary markers: The instructions do not define specific delimiters or instructions to prevent the agent from interpreting embedded commands within the captured learning data. * Capability inventory: The skill possesses the capability to write and modify markdown files within the team's data repositories (Wachi Brain, Engram). * Sanitization: The skill lacks explicit sanitization or validation steps to filter potential injection patterns from the user-supplied summaries before they are documented.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 04:39 PM
Security Audit — agent-trust-hub — wachi-compound