printing-press-retro
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill packages and uploads manuscript directories and source code archives to an external public file-sharing service (
catbox.moe) viacurl. While secret scrubbing routines are implemented, utilizing an anonymous public hosting platform for project logs and source code creates a risk of exposing sensitive or proprietary data. - [INDIRECT_PROMPT_INJECTION]: The skill ingests history logs and conversational data to identify defects, presenting an indirect prompt injection vulnerability surface.
- Ingestion points: Ingests conversation transcripts from
~/.claude/projects/<project-slug>/*.jsonland build/smoke logs from$RUN_DIR/proofs/inphases/01-gather-evidence.mdandphases/02-mine-the-session.md. - Boundary markers: Lacks explicit boundary delimiters or system instructions to encapsulate historical log text as untrusted data.
- Capability inventory: Possesses capabilities to execute arbitrary local shell commands via the Bash tool, interact with GitHub repositories via the
ghCLI, and post files viacurl. - Sanitization: Contains regex-based scanning for credentials and basic PII shapes (
references/secret-scrubbing.md), but lacks validation or structural escaping to neutralize embedded natural language instructions before processing.
Audit Metadata