experience-manager

Pass

Audited by Gen Agent Trust Hub on Apr 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute git commands (git rev-parse and git branch) to determine the project root and current development branch. These are localized environment checks.
  • [PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection through its knowledge management workflow.
  • Ingestion points: Reads data from CLAUDE.md, AGENT.md, MEMORY.md, and retrospective markdown files in memory/retrospectives/ (as described in detailed-guide.md).
  • Boundary markers: Absent; the skill does not use specific delimiters or protective instructions to wrap external content.
  • Capability inventory: Authorized to use Bash, Write, Edit, and Read tools, which provides the ability to modify project-wide configuration and instructions.
  • Sanitization: Absent; the skill lacks logic to filter or validate ingested experience data before it is persisted in behavior-modifying files.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 19, 2026, 10:00 AM
Security Audit — agent-trust-hub — experience-manager