system-overview
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill specifies the use of local Python scripts to perform system operations such as setting up the environment and recalling historical data (e.g.,
uv run python opc/scripts/setup/wizard.pyandopc/scripts/recall_temporal_facts.py).- [INDIRECT_PROMPT_INJECTION]: The skill architecture is designed to ingest data from past sessions and external files, which represents an indirect prompt injection surface. - Ingestion points: Data is pulled from a PostgreSQL memory layer, 'continuity ledgers' in the
thoughts/ledgers/directory, and YAML handoff files inthoughts/shared/handoffs/. - Boundary markers: The system overview does not explicitly define delimiters or instructions for the agent to ignore embedded commands within this historical data.
- Capability inventory: The skill uses Python script execution, file system access for ledger/handoff management, and subagent coordination.
- Sanitization: There is no mention of sanitization or filtering of the historical facts or handoff content before they are injected into the agent's context.
Audit Metadata