ruminate
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes historical conversation logs which may contain untrusted data or previous malicious attempts. \n
- Ingestion points: Reads JSONL files from sensitive directories
~/.claude/projects/and~/.codex/sessions/viascripts/extract-conversations.py. \n - Boundary markers: The extraction script adds structured headers like
[USER]:,[ASSISTANT]:,[PROVIDER]:, and[SOURCE_FILE]:to the processed text, providing context to analysis agents. \n - Capability inventory: The skill can spawn sub-agents (
TeamCreate), execute shell scripts, run Python code, and write updates to brain files and other skills'SKILL.mdfiles (Step 6). \n - Sanitization: The Python script performs basic cleaning (whitespace, system reminder filtering) and truncates message length, but does not perform instruction filtering or safety checks on the message content. \n- [COMMAND_EXECUTION]: The skill executes multiple commands to process data. \n
- Evidence:
SKILL.mdinvokes a snapshot script (sh .claude/skills/meditate/scripts/snapshot.sh) and the local extraction script (python3 "$SKILL_DIR/scripts/extract-conversations.py"). It also performs directory cleanup viarm -rfand creates temporary files in/tmp/. These operations are consistent with the documented process.
Audit Metadata