context-fundamentals
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The context assembly logic in
scripts/context_manager.pyconcatenates multiple inputs, including task descriptions and retrieved documents, into a single context string without applying boundary delimiters or instructions to ignore embedded commands. This creates a vulnerability surface where untrusted content in retrieved documents could trigger indirect prompt injection. - [INDIRECT_PROMPT_INJECTION]: The
ProgressiveDisclosureManagerclass inscripts/context_manager.pyfacilitates reading files from the filesystem without validating paths against the intended base directory. This allows an agent to potentially access sensitive files if manipulated via malicious input. - Ingestion points: The
task,system_prompt, anddocumentsinputs inbuild_agent_contextand the file paths inProgressiveDisclosureManagermethods. - Boundary markers: Absent in the
ContextBuilderconcatenation logic withinscripts/context_manager.py. - Capability inventory: Arbitrary file read access via the
ProgressiveDisclosureManager.load_summaryandload_detailmethods. - Sanitization: The script lacks path validation and input sanitization for external data sources.
Audit Metadata