context-fundamentals

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion and interpolation of untrusted external content (retrieved documents and user-supplied tasks) into the agent's context window through the build_agent_context function and ContextBuilder class in scripts/context_manager.py.
  • Ingestion points: The build_agent_context function accepts a documents list and a task string which are directly concatenated into the final context string.
  • Boundary markers: While the documentation in SKILL.md and references/context-components.md recommends using XML-like tags (e.g., <BACKGROUND_INFORMATION>) to delimit sections, the Python implementation does not programmatically enforce these boundaries or apply "ignore instructions" directives.
  • Capability inventory: The skill includes local file system read capabilities via the ProgressiveDisclosureManager class but lacks network access or shell execution tools.
  • Sanitization: The implementation performs no character escaping or content filtering to prevent embedded instructions from influencing model behavior.
  • [DATA_EXFILTRATION]: The ProgressiveDisclosureManager class in scripts/context_manager.py contains methods (load_summary, load_detail) that perform unvalidated file reads using the standard open() function. Although a base_dir is specified in the constructor, the load_detail method accepts an arbitrary detail_path string without performing path traversal checks (e.g., checking for ../), which could allow an agent to read sensitive local files if the path is manipulated.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:02 PM
Security Audit — agent-trust-hub — context-fundamentals