stow
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill facilitates indirect prompt injection by capturing summarized data from the current conversation and persisting it into project memory files intended for consumption in future agent sessions. Malicious instructions embedded in the chat could thus be archived and executed later.\n
- Ingestion points: Conversation history (chat context).\n
- Boundary markers: Absent. The skill does not specify the use of delimiters or 'ignore' prefixes when writing summarized findings to local files.\n
- Capability inventory: File system read/write access (modifying documentation, task lists, and configuration files) and potential network operations through external routing tools.\n
- Sanitization: Absent. No technical validation or escaping is specified for the content extracted from the conversation before it is saved to disk.\n- [DATA_EXFILTRATION]: The skill establishes a functional path for exfiltrating project knowledge to external destinations such as issue trackers or ticketing systems. Although this is triggered by explicit user instruction, the capability involves sending internal project facts to third-party hosted services.\n- [COMMAND_EXECUTION]: The skill requires the agent to perform file system operations and potentially execute external tool commands to maintain project conventions, update trackers, and manage the local .gitignore file.
Audit Metadata