agent-context-isolation

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill promotes a file-based coordination pattern where outputs from one sub-agent are stored in files and subsequently read by other agents in a pipeline. This creates a surface for indirect prompt injection if the content produced by a sub-agent contains instructions that the reading agent might mistakenly follow.
  • Ingestion points: Files stored in .claude/cache/agents/ and specific output paths like src/module.ts.
  • Boundary markers: The rules do not provide guidance on using delimiters or explicit instructions to ignore embedded commands within the processed files.
  • Capability inventory: The skill leverages Bash capabilities for polling file system changes and executing test suites.
  • Sanitization: There is no mention of sanitizing or validating external content before interpolation into subsequent agent prompts.
  • [COMMAND_EXECUTION]: The skill instructs the agent to use shell commands for monitoring and verification, including ls, find, wc, and bun test. While these are standard utilities, they are executed based on the logic described in the coordination rules.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:10 PM
Security Audit — agent-trust-hub — agent-context-isolation