salvage

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes session files and prior work history to generate salvage reports, which presents a surface for instructions hidden in those files to influence the agent.
  • Ingestion points: The skill reads 'prior phase sections' from session files as described in SKILL.md (Session Handoff section).
  • Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from following commands embedded in the work being salvaged.
  • Capability inventory: The skill is instructed to write to a knowledge corpus ('metis/guardrails') using vendor-specific tools ('RNA/OH tools') as defined in SKILL.md (Step 4).
  • Sanitization: No sanitization or filtering logic is specified for the input data before it is processed by the LLM.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 07:20 PM
Security Audit — agent-trust-hub — salvage