weekly-retro

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using git and the gh CLI for gathering logs, searching issues, and managing the project backlog. It uses repository paths and project identifiers sourced from the user's CLAUDE.md configuration to perform these operations.
  • [DATA_EXFILTRATION]: The skill is designed to access and read 'canonical files' (such as data.md or insights.md) which are defined as holding sensitive business information including revenue, prices, and strategic findings. While this access is intended for the retrospective process, it creates a potential surface for the exposure of private business data.
  • [PROMPT_INJECTION]: The skill processes untrusted external data from git commit messages and GitHub issue metadata (SKILL.md, Phase 1). This content is ingested into the agent's context without explicit sanitization or boundary markers. While the skill includes 'Iron Rules' to verify facts and avoid assumptions, the presence of untrusted content in the workflow provides a surface for indirect prompt injection that could influence the agent's summaries or issue creation. Key capabilities include file-system writes, git commits, and GitHub issue generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 08:56 PM
Security Audit — agent-trust-hub — weekly-retro