recall-reasoning

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local Python and shell scripts to perform searches.
  • Evidence: uv run python scripts/core/artifact_query.py and bash "$CLAUDE_PROJECT_DIR/.claude/scripts/search-reasoning.sh".
  • Context: These scripts appear to be internal tools for managing project state and reasoning history.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from previous sessions which could contain instructions from external sources if they were part of the previous task context.
  • Ingestion points: Reads handoffs, plans, and build reasoning logs via artifact_query.py and search-reasoning.sh.
  • Boundary markers: None specified in the instructions.
  • Capability inventory: Can execute local Python scripts and shell commands described in SKILL.md.
  • Sanitization: No explicit sanitization or filtering of recalled text is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:22 PM
Security Audit — agent-trust-hub — recall-reasoning