project-context
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a local Bash script at
scripts/project-context.shto perform environment checks and bootstrap project files. The script implements safe file-handling practices, such as usingmktempandmvfor atomic writes and checking for file existence before creation to prevent data loss. It also mentions integration with other tools in the same suite for linting and validation. - [INDIRECT_PROMPT_INJECTION]: The skill processes project-specific documentation and wiki files to build context for the agent. This represents a potential surface for indirect prompt injection if an attacker were to commit malicious instructions to these files.
- Ingestion points: The agent is instructed to read
.brain/index.md,.brain/architecture.md,AGENTS.md, andTODO.mdto understand project state. - Boundary markers: The skill does not currently implement explicit boundary markers or instructions to ignore embedded commands within these processed files.
- Capability inventory: The skill has the capability to write to the file system using the
project-context.shscript. - Sanitization: There is no explicit sanitization of external content before it is processed by the agent. This finding is inherent to the skill's primary purpose of providing project context.
- [EXTERNAL_DOWNLOADS]: The documentation references an external project pattern (Karpathy's LLM Wiki) hosted on a well-known service (GitHub Gist). This reference is purely informative and does not involve automated code execution.
Audit Metadata