context-engine
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from a local file (
~/.claude/company-context.md) which acts as an attack surface for indirect prompt injection. The skill includes a comprehensiveanonymization-protocol.mdreference to sanitize this data before external tool use. Ingestion points:SKILL.md. Boundary markers: Internal status notes. Capability inventory: No dangerous local commands or network scripts present. Sanitization: Detailed anonymization rules for financial and personal data.
Audit Metadata