context-engine

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from a local file (~/.claude/company-context.md) which acts as an attack surface for indirect prompt injection. The skill includes a comprehensive anonymization-protocol.md reference to sanitize this data before external tool use. Ingestion points: SKILL.md. Boundary markers: Internal status notes. Capability inventory: No dangerous local commands or network scripts present. Sanitization: Detailed anonymization rules for financial and personal data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 12:32 PM
Security Audit — agent-trust-hub — context-engine