sales-shortwave
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill implements a self-updating knowledge base by reading from and appending to 'references/learnings.md'. This ingestion of data from past interactions creates a surface for indirect prompt injection. \n
- Ingestion points: 'references/learnings.md' and user-supplied descriptions in 'SKILL.md' \n
- Boundary markers: Absent \n
- Capability inventory: The agent is instructed to append new gotchas or tips to 'references/learnings.md' \n
- Sanitization: None mentioned.\n- [DATA_EXFILTRATION]: The skill provides instructions to access local application log files ('~/Library/Logs/Shortwave/main.log' and '%APPDATA%\Shortwave\logs\main.log') for troubleshooting. Accessing these files could lead to the exposure of sensitive user metadata or session information to the agent context.\n- [NO_CODE]: The skill consists entirely of Markdown-based instructions and reference files. It does not contain or execute any scripts, binaries, or automated shell commands.
Audit Metadata