agent-fault-retrospective
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill establishes a mechanism for indirect prompt injection by persisting user-influenced rules into global agent configuration files.
- Ingestion points: User feedback regarding agent faults, overreach, or misunderstanding (SKILL.md).
- Boundary markers: Absent. The skill does not define specific delimiters or "ignore instructions" warnings to prevent the agent from obeying instructions embedded within the user's fault description.
- Capability inventory: The skill possesses file-write capabilities targeting sensitive global instruction files such as AGENTS.md, CLAUDE.md, GEMINI.md, and .cursor/rules/ (SKILL.md, Workflow Sections 2 and 5).
- Sanitization: Absent. The workflow relies on user confirmation rather than automated sanitization or validation of the generated rules before persistence.
Audit Metadata