insights
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from project-local files (
CLAUDE.md,.claude/LEARNED.md, and.claude/learning-log.md) which serve as a persistent memory of past interactions and learnings. - Ingestion points: File contents are read in
SKILL.mdto compute statistics. - Boundary markers: Content is ingested directly without specific markers to separate data from instructions.
- Capability inventory: The skill uses
cat,grep, andgitto analyze local logs. It does not have capabilities for network exfiltration, file system modifications, or privilege escalation. - Sanitization: No explicit sanitization or filtering is applied to the log data before processing.
Audit Metadata