lov-auto-context
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is configured to scan conversation transcripts for 'unpersisted feedback or preferences' and automatically write them to project memory files. This capability can be leveraged to persist malicious instructions into the agent's long-term memory if such instructions are present in the processed session data.
- Ingestion points: Reads and evaluates the current session transcript (file path:
SKILL.md). - Boundary markers: None identified for distinguishing session data from instructions during the persistence process.
- Capability inventory: Utilizes the
Edittool to write markdown files and update index files (MEMORY.md). - Sanitization: No explicit sanitization or filtering of extracted feedback is described.
- [COMMAND_EXECUTION]: The skill performs automated file system operations using the
Edittool. It automatically writes memory files and updates index pointers when it detects unpersisted preferences. While sensitive edits to global or project-levelCLAUDE.mdfiles are mitigated by a mandatory diff-and-confirm flow, the automated memory updates represent persistent state modification driven by inferred session intent.
Audit Metadata