retro

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to read and analyze session logs, which serves as a potential entry point for indirect prompt injection. If session logs contain attacker-controlled data, the agent might inadvertently adopt malicious instructions when formulating suggestions for the repository's steering files.
  • Ingestion points: Reads and processes session logs from the local machine in SKILL.md.
  • Boundary markers: Absent. The instructions do not specify the use of delimiters or distinct sections to isolate log content from the agent's operational logic.
  • Capability inventory: The skill suggests modifications to critical repository configuration files like CLAUDE.md, AGENTS.md, and CODING_STANDARDS.md.
  • Sanitization: Absent. There are no instructions provided to filter, validate, or sanitize the content found within the logs before it is used to generate recommendations.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 01:51 PM
Security Audit — agent-trust-hub — retro