experience-manager
Pass
Audited by Gen Agent Trust Hub on Apr 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the Bash tool to execute git commands (
git rev-parseandgit branch) to determine the project root and current development branch. These are localized environment checks. - [PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection through its knowledge management workflow.
- Ingestion points: Reads data from
CLAUDE.md,AGENT.md,MEMORY.md, and retrospective markdown files inmemory/retrospectives/(as described indetailed-guide.md). - Boundary markers: Absent; the skill does not use specific delimiters or protective instructions to wrap external content.
- Capability inventory: Authorized to use
Bash,Write,Edit, andReadtools, which provides the ability to modify project-wide configuration and instructions. - Sanitization: Absent; the skill lacks logic to filter or validate ingested experience data before it is persisted in behavior-modifying files.
Audit Metadata