memorize
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill harvests external inputs (conversation history, reflection outputs, critique findings, and project files) to compile a persistent playbook (
CLAUDE.md). This creates an indirect prompt injection surface where malicious text in the ingested data could influence future agent behavior. - Ingestion points: Processes conversation history, outputs from
/reflexion:reflectand/reflexion:critique, and specific target files during the Phase 1 Context Harvesting step. - Boundary markers: Lacks explicit structural delimiters or instructions to ignore embedded commands within the harvested text inputs.
- Capability inventory: Modifies and writes to the persistent project context file
CLAUDE.md, which is continuously read by the agent in subsequent sessions. - Sanitization: While it includes a policy constraint against storing secrets, tokens, or PII, it lacks input filtering or validation mechanisms to sanitize untrusted instructions or prompt injection payloads.
Audit Metadata