mpm-init

Pass

Audited by Gen Agent Trust Hub on Mar 30, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect prompt injection surface identified due to processing of untrusted external data.
  • Ingestion points: Analyzes git history (commit patterns and messages) and local logs in .claude-mpm/resume-logs/ and .claude-mpm/responses/ (SKILL.md).
  • Boundary markers: Absent; no instructions are provided to the agent to treat git data or log entries as untrusted or to ignore embedded instructions.
  • Capability inventory: The skill modifies project files (CLAUDE.md, .gitignore), manages tool configurations, and executes CLI commands via a git log wrapper (SKILL.md).
  • Sanitization: Absent; no explicit data validation or escaping is mentioned for content retrieved from the git history or internal logs.
  • [COMMAND_EXECUTION]: The skill documentation indicates direct CLI execution for system commands. Evidence: The 'catchup' mode is described as 'Direct CLI execution' using a 'git log wrapper' (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 30, 2026, 02:30 PM
Security Audit — agent-trust-hub — mpm-init