salvage
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes session files and prior work history to generate salvage reports, which presents a surface for instructions hidden in those files to influence the agent.
- Ingestion points: The skill reads 'prior phase sections' from session files as described in
SKILL.md(Session Handoff section). - Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from following commands embedded in the work being salvaged.
- Capability inventory: The skill is instructed to write to a knowledge corpus ('metis/guardrails') using vendor-specific tools ('RNA/OH tools') as defined in
SKILL.md(Step 4). - Sanitization: No sanitization or filtering logic is specified for the input data before it is processed by the LLM.
Audit Metadata