Ahoy
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is restricted to history-only operations. It contains explicit instructions to avoid external data gathering, network calls (e.g., GitHub, browsers), and file system modifications.\n- [INDIRECT_PROMPT_INJECTION]: The skill identifies and processes untrusted data from the chat history to generate recaps.\n
- Ingestion points: Visible session history including previous user and system messages as defined in SKILL.md.\n
- Boundary markers: Includes specific logic to distinguish between user-authored ("captain") messages and crew, system, or teammate messages to define recap intervals.\n
- Capability inventory: The skill explicitly lacks external tool access (no subprocess, network, or file writes allowed).\n
- Sanitization: None present, though the risk is low due to the complete lack of executable tools.
Audit Metadata