context-fundamentals
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion and interpolation of untrusted external content (retrieved documents and user-supplied tasks) into the agent's context window through the
build_agent_contextfunction andContextBuilderclass inscripts/context_manager.py. - Ingestion points: The
build_agent_contextfunction accepts adocumentslist and ataskstring which are directly concatenated into the final context string. - Boundary markers: While the documentation in
SKILL.mdandreferences/context-components.mdrecommends using XML-like tags (e.g.,<BACKGROUND_INFORMATION>) to delimit sections, the Python implementation does not programmatically enforce these boundaries or apply "ignore instructions" directives. - Capability inventory: The skill includes local file system read capabilities via the
ProgressiveDisclosureManagerclass but lacks network access or shell execution tools. - Sanitization: The implementation performs no character escaping or content filtering to prevent embedded instructions from influencing model behavior.
- [DATA_EXFILTRATION]: The
ProgressiveDisclosureManagerclass inscripts/context_manager.pycontains methods (load_summary,load_detail) that perform unvalidated file reads using the standardopen()function. Although abase_diris specified in the constructor, theload_detailmethod accepts an arbitrarydetail_pathstring without performing path traversal checks (e.g., checking for../), which could allow an agent to read sensitive local files if the path is manipulated.
Audit Metadata