skills/netresearch/retro-skill/retro/Gen Agent Trust Hub

retro

Pass

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's core functionality involves ingesting data from external, potentially untrusted sources.
  • Ingestion points: collect-review-findings.py fetches review threads, bodies, and comments from GitHub and GitLab. scan-memory-inventory.py reads project-local memory files. opencode-transcript.py reads session databases.
  • Boundary markers: The scripts do not appear to wrap this external content in clear delimiters or include explicit instructions for the model to ignore embedded commands, though documentation in feedback-contract.md acknowledges the risk.
  • Capability inventory: The skill uses subprocess.run to call git, gh, and glab, and utilizes the Write and Edit tools to modify project files and open PRs.
  • Sanitization: The mask-secrets.py utility provides extensive masking for various credential formats (AWS, GitHub, GitLab, etc.). collect-review-findings.py uses a oneline function to strip control characters from foreign content.
  • [EXTERNAL_DOWNLOADS]: The script check-upstream-sources.py performs network probes (using urllib.request.urlopen) to arbitrary URLs extracted from markdown documentation. While this is used for link validation during audits, it represents a network activity surface using data derived from potentially user-controlled or external markdown content.
  • [COMMAND_EXECUTION]: Multiple scripts (check-eval-samples.py, collect-review-findings.py, scan-cross-session.py, derive-session-scope.py) execute system commands like git, gh, and glab. Although they use list-based arguments and --end-of-options to prevent shell injection, these scripts provide the agent with broad capabilities to interact with local and remote repositories.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 8, 2026, 07:05 AM