cross-campaign

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONNO_CODE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use the camp utility, alongside standard tools like jq and cat, to manage file paths and navigate between project directories. All operations described are local shell commands within the user's environment.\n- [PROMPT_INJECTION]: The skill facilitates reading content from external project directories, which constitutes an indirect prompt injection surface. \n
  • Ingestion points: The cat command and camp transfer utility are used to read or copy files from projects outside the current active campaign scope. \n
  • Boundary markers: No specific delimiters or safety warnings are provided for the agent when handling content from these external sources. \n
  • Capability inventory: The agent is granted the ability to read files, list directory structures, and write/copy data across local project boundaries. \n
  • Sanitization: There are no explicit instructions for the agent to sanitize or validate the data retrieved from external files before processing it.\n- [NO_CODE]: The skill is composed of markdown-based instructions and triggers. It does not package or execute any hidden scripts, binaries, or external dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 06:04 AM
Security Audit — agent-trust-hub — cross-campaign