ai-forge-recap
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes external instruction files (skills, agents, and references) which are untrusted data sources. This creates a potential surface where malicious content in the audited files could influence the agent's recap or lead to incorrect tool invocations. \n- Ingestion points: Reads file paths provided by the environment, targeting 'SKILL.md', '.agent.md', and 'references/' content. \n- Boundary markers: Absent. The instructions do not define delimiters or explicit rules to isolate audited content from the agent's reasoning process. \n- Capability inventory: The skill can trigger updates to frontmatter through 'ai-forge-apply' and to the file body through 'ai-forge-update', creating a cycle where read data can drive write operations. \n- Sanitization: Absent. The skill does not describe any validation or filtering of the ingested content before it is used for comparison and reporting.
Audit Metadata