ljg-relationship

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests highly sensitive, user-provided relationship details (narratives, emotional states, background histories) in SKILL.md. It does not define boundaries or sanitization steps before processing this raw data, exposing the conversation to potential conversational or structured schema manipulation.
  • [COMMAND_EXECUTION]: In Step 6 of SKILL.md, the instructions dictate running a local system shell command (date +%Y%m%dT%H%M%S) and writing the compiled information into files under the local directory structure (~/Documents/notes/). Unsanitized content derived from conversational inputs can lead to uncontrolled file operations or local context manipulation if coupled with downstream agent capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:31 AM
Security Audit — agent-trust-hub — ljg-relationship