agent-context-isolation
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill promotes a file-based coordination pattern where outputs from one sub-agent are stored in files and subsequently read by other agents in a pipeline. This creates a surface for indirect prompt injection if the content produced by a sub-agent contains instructions that the reading agent might mistakenly follow.
- Ingestion points: Files stored in
.claude/cache/agents/and specific output paths likesrc/module.ts. - Boundary markers: The rules do not provide guidance on using delimiters or explicit instructions to ignore embedded commands within the processed files.
- Capability inventory: The skill leverages
Bashcapabilities for polling file system changes and executing test suites. - Sanitization: There is no mention of sanitizing or validating external content before interpolation into subsequent agent prompts.
- [COMMAND_EXECUTION]: The skill instructs the agent to use shell commands for monitoring and verification, including
ls,find,wc, andbun test. While these are standard utilities, they are executed based on the logic described in the coordination rules.
Audit Metadata