context-fundamentals

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The context assembly logic in scripts/context_manager.py concatenates multiple inputs, including task descriptions and retrieved documents, into a single context string without applying boundary delimiters or instructions to ignore embedded commands. This creates a vulnerability surface where untrusted content in retrieved documents could trigger indirect prompt injection.
  • [INDIRECT_PROMPT_INJECTION]: The ProgressiveDisclosureManager class in scripts/context_manager.py facilitates reading files from the filesystem without validating paths against the intended base directory. This allows an agent to potentially access sensitive files if manipulated via malicious input.
  • Ingestion points: The task, system_prompt, and documents inputs in build_agent_context and the file paths in ProgressiveDisclosureManager methods.
  • Boundary markers: Absent in the ContextBuilder concatenation logic within scripts/context_manager.py.
  • Capability inventory: Arbitrary file read access via the ProgressiveDisclosureManager.load_summary and load_detail methods.
  • Sanitization: The script lacks path validation and input sanitization for external data sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:10 AM
Security Audit — agent-trust-hub — context-fundamentals