are-decisions-from-this-session-saved
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes the entire session transcript as its primary data source to identify decisions. If the transcript contains untrusted content (e.g., data previously retrieved from external sources or malicious user inputs), it could potentially influence the agent's judgment or lead to the recording of malicious instructions into project files.
- Ingestion points: The conversation history and session transcript (processed in the Inventory step in SKILL.md).
- Boundary markers: Absent. The skill does not instruct the agent to use specific delimiters or to ignore potential instructions embedded within the transcript when performing the inventory.
- Capability inventory: The skill uses
AskUserQuestionand interacts with other skills (/wayfinder,/decisions-to-specs) to read and write to project files such as maps, tickets, and specifications. - Sanitization: Absent. There are no instructions for sanitizing or validating the content extracted from the transcript before it is proposed for recording.
Audit Metadata