context-engineering

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPERSISTENCE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill promotes a strategy of reading from external files like NOTES.md, CLAUDE.md, and .claude/critical-context.md to maintain session state. This creates a surface where malicious instructions embedded in these files (e.g., via a compromised repository or pull request) could influence the agent's behavior.
  • Ingestion points: NOTES.md, CLAUDE.md, .claude/memory/, and .claude/critical-context.md as described in SKILL.md.
  • Boundary markers: The skill does not suggest the use of delimiters or instructions to ignore embedded commands within these persistent files.
  • Capability inventory: The skill references the use of grep, Glob, cat, and the creation of subagents to process information.
  • Sanitization: There is no mention of sanitizing or validating the content of external files before injecting them into the primary context.
  • [COMMAND_EXECUTION]: The skill includes an example configuration for a PostCompact hook that executes the shell command cat .claude/critical-context.md. While used for context management, this involves shell-level execution of file reads.
  • [PERSISTENCE]: The skill describes methods to ensure information survives session boundaries and compaction events using durable storage such as .claude/memory/ and CLAUDE.md. This represents a persistence mechanism for agent instructions, allowing state to remain active across different tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 05:34 AM
Security Audit — agent-trust-hub — context-engineering