second-brain-reflection

Pass

Audited by Gen Agent Trust Hub on May 21, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to Indirect Prompt Injection through its 'Reflection Protocol'. It instructs the agent to ingest data from completed missions, pull requests, and experiments to extract rules for future use. An attacker could embed malicious instructions in these data sources which, when processed, would be stored as permanent 'Rules' or 'Stratagems' in the agent's memory files, influencing behavior in all subsequent sessions.
  • Ingestion points: The agent reads content from 'Mission, PR, or Experiment' logs and descriptions to perform the audit.
  • Boundary markers: Absent. There are no instructions to differentiate between the agent's own task metadata and potentially untrusted content within the mission logs or PR bodies.
  • Capability inventory: The skill directs the agent to write to sensitive locations including the user's home directory (~/.gemini/GEMINI.md) and project-specific configuration files (./GEMINI.md).
  • Sanitization: Absent. The skill does not provide any validation or filtering logic to ensure that extracted lessons are benign before they are persisted to the global memory tier.
Audit Metadata
Risk Level
SAFE
Analyzed
May 21, 2026, 08:11 AM
Security Audit — agent-trust-hub — second-brain-reflection