sidequest
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a 'rebuild' mode where a subagent audits the conversation history (
transcript.jsonl) to reconstruct the session's structured task map. This process is vulnerable to indirect prompt injection if the conversation history contains malicious instructions designed to manipulate the subagent's analysis or the resulting structured data. - Ingestion points: The subagent reads the conversation transcript (
transcript.jsonl) as part of the Mode B workflow described inSKILL.mdandresources/auditor_prompt.txt. - Boundary markers: Absent. The
resources/auditor_prompt.txtinstructions do not define clear delimiters or provide the subagent with guidelines to ignore or escape instructions embedded within the transcript content. - Capability inventory: The skill possesses the capability to write to the file system (
sidequest.jsonandsidequest.md) through theSessionStoreclass inlib/src/storage/session_store.dartand perform batch state mutations vialib/src/cli/command_runner.dart. - Sanitization: Absent. The skill decodes JSON payloads returned by the auditor subagent and merges them into the local session state without verifying the content for injection attempts or malicious task descriptions.
Audit Metadata