document
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes research data and chat context which presents an attack surface for indirect instructions. Ingestion points: Reads research files and plans from the .agentflow/ directory and the current chat history. Boundary markers: No explicit separators or 'ignore' instructions are used for source content. Capability inventory: Performs file system access including reading, writing, and deleting files within the .agentflow/ directory. Sanitization: Instructs the agent to redact secrets from the final output.
- [SAFE]: The identified functionality is consistent with the skill's primary purpose as a documentation and cleanup utility. The file operations are limited to relevant project directories and no signs of malicious exfiltration, remote code execution, or obfuscation were found.
Audit Metadata