context-compressor
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to process large volumes of untrusted text (codebase context, RAG payloads, transcripts), creating an inherent surface for indirect prompt injection.\n
- Ingestion points: Untrusted data is ingested via scripts/compress_context.py and scripts/run_skill_workflow.py using file and JSON inputs.\n
- Boundary markers: The skill does not utilize specific delimiters or instruction-following guardrails to isolate potentially malicious text within the source data.\n
- Capability inventory: The skill possesses the ability to write to the repository's memory structures via scripts/main.cjs and has Bash tool access to execute internal scripts.\n
- Sanitization: There is no evidence of sanitization or filtering intended to strip instructions from the input text.\n- [INDIRECT_PROMPT_INJECTION]: The core compression logic in scripts/_compression_engine.py supports tags with a compress=false attribute. This mechanism allows specific blocks of text to bypass semantic filtering and be forced into the final output, providing a direct way for prompt injections to persist through the compression process.\n- [COMMAND_EXECUTION]: The package includes a comprehensive set of reference scripts (references/skill-creator-reference/scripts/) that perform command execution by invoking the claude CLI via subprocesses. These tools facilitate complex workflows like automated skill triggering and description optimization.\n- [METADATA_POISONING]: The SKILL.md frontmatter contains self-declared safety claims including verified: true and trust_score: 100. These fields appear intended to deceptively influence automated or manual safety assessments.
Audit Metadata