session-summary

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local script at ${PLUGIN_ROOT}/scripts/dae_resolve.py to determine project scope. This is a local operation for path resolution.
  • [PROMPT_INJECTION]: Indirect prompt injection surface exists via data ingestion.
  • Ingestion points: Reads from handoffs/*.md and conversation context (SKILL.md).
  • Boundary markers: Absent; no delimiters used for ingested content.
  • Capability inventory: File system append and local script execution (SKILL.md).
  • Sanitization: Absent; ingested content is not validated.
  • [SAFE]: References a design document on Notion, a well-known service.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 04:56 PM
Security Audit — agent-trust-hub — session-summary