are-decisions-from-this-session-saved

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes the entire session transcript as its primary data source to identify decisions. If the transcript contains untrusted content (e.g., data previously retrieved from external sources or malicious user inputs), it could potentially influence the agent's judgment or lead to the recording of malicious instructions into project files.
  • Ingestion points: The conversation history and session transcript (processed in the Inventory step in SKILL.md).
  • Boundary markers: Absent. The skill does not instruct the agent to use specific delimiters or to ignore potential instructions embedded within the transcript when performing the inventory.
  • Capability inventory: The skill uses AskUserQuestion and interacts with other skills (/wayfinder, /decisions-to-specs) to read and write to project files such as maps, tickets, and specifications.
  • Sanitization: Absent. There are no instructions for sanitizing or validating the content extracted from the transcript before it is proposed for recording.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 01:31 PM
Security Audit — agent-trust-hub — are-decisions-from-this-session-saved