agent-fault-retrospective

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill establishes a mechanism for indirect prompt injection by persisting user-influenced rules into global agent configuration files.
  • Ingestion points: User feedback regarding agent faults, overreach, or misunderstanding (SKILL.md).
  • Boundary markers: Absent. The skill does not define specific delimiters or "ignore instructions" warnings to prevent the agent from obeying instructions embedded within the user's fault description.
  • Capability inventory: The skill possesses file-write capabilities targeting sensitive global instruction files such as AGENTS.md, CLAUDE.md, GEMINI.md, and .cursor/rules/ (SKILL.md, Workflow Sections 2 and 5).
  • Sanitization: Absent. The workflow relies on user confirmation rather than automated sanitization or validation of the generated rules before persistence.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 09:44 AM
Security Audit — agent-trust-hub — agent-fault-retrospective