lov-auto-context

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is configured to scan conversation transcripts for 'unpersisted feedback or preferences' and automatically write them to project memory files. This capability can be leveraged to persist malicious instructions into the agent's long-term memory if such instructions are present in the processed session data.
  • Ingestion points: Reads and evaluates the current session transcript (file path: SKILL.md).
  • Boundary markers: None identified for distinguishing session data from instructions during the persistence process.
  • Capability inventory: Utilizes the Edit tool to write markdown files and update index files (MEMORY.md).
  • Sanitization: No explicit sanitization or filtering of extracted feedback is described.
  • [COMMAND_EXECUTION]: The skill performs automated file system operations using the Edit tool. It automatically writes memory files and updates index pointers when it detects unpersisted preferences. While sensitive edits to global or project-level CLAUDE.md files are mitigated by a mandatory diff-and-confirm flow, the automated memory updates represent persistent state modification driven by inferred session intent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:05 PM
Security Audit — agent-trust-hub — lov-auto-context