printing-press-retro

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill packages and uploads manuscript directories and source code archives to an external public file-sharing service (catbox.moe) via curl. While secret scrubbing routines are implemented, utilizing an anonymous public hosting platform for project logs and source code creates a risk of exposing sensitive or proprietary data.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests history logs and conversational data to identify defects, presenting an indirect prompt injection vulnerability surface.
  • Ingestion points: Ingests conversation transcripts from ~/.claude/projects/<project-slug>/*.jsonl and build/smoke logs from $RUN_DIR/proofs/ in phases/01-gather-evidence.md and phases/02-mine-the-session.md.
  • Boundary markers: Lacks explicit boundary delimiters or system instructions to encapsulate historical log text as untrusted data.
  • Capability inventory: Possesses capabilities to execute arbitrary local shell commands via the Bash tool, interact with GitHub repositories via the gh CLI, and post files via curl.
  • Sanitization: Contains regex-based scanning for credentials and basic PII shapes (references/secret-scrubbing.md), but lacks validation or structural escaping to neutralize embedded natural language instructions before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 08:57 PM
Security Audit — agent-trust-hub — printing-press-retro