retro
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to read and analyze session logs, which serves as a potential entry point for indirect prompt injection. If session logs contain attacker-controlled data, the agent might inadvertently adopt malicious instructions when formulating suggestions for the repository's steering files.
- Ingestion points: Reads and processes session logs from the local machine in
SKILL.md. - Boundary markers: Absent. The instructions do not specify the use of delimiters or distinct sections to isolate log content from the agent's operational logic.
- Capability inventory: The skill suggests modifications to critical repository configuration files like
CLAUDE.md,AGENTS.md, andCODING_STANDARDS.md. - Sanitization: Absent. There are no instructions provided to filter, validate, or sanitize the content found within the logs before it is used to generate recommendations.
Audit Metadata