retro
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes historical session transcripts, which constitutes an ingestion point for untrusted data that could contain malicious instructions designed to trigger during a retrospective.
- Ingestion points: The skill reads current and past session transcripts via the
agents-introspectionskill to identify friction points and recurrence (documented in sections 1, 2, and 4). - Boundary markers: The instructions explicitly state to follow
agents-introspection's retrieval, secret-handling, and disclosure rules, providing some scoping, though specific delimiters for the injected content are not defined within this skill. - Capability inventory: The agent has the capability to write changes to steering files (
AGENTS.md,CLAUDE.md), automated checks (justfile,package.json,Makefile, hooks), and skill source files (documented in sections 5, 6, and 7). It also executes repository check commands to validate changes. - Sanitization: Modifications are gated by a requirement for explicit user approval ("Change files only when the user explicitly asks to apply candidates"), which serves as a human-in-the-loop sanitization step.
Audit Metadata