context-optimization
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from tool outputs and user messages to perform summarization and compaction, which is a vector for indirect prompt injection.
- Ingestion points:
summarize_contentandObservationStore.maskinscripts/compaction.pytake arbitrary strings as input for processing. - Boundary markers: The implementation lacks explicit delimiters or instructions within the summarization logic to prevent the agent from following instructions embedded in the summarized data.
- Capability inventory: The skill does not possess high-risk capabilities; no network operations, file writing, or command execution tools were found in the provided scripts.
- Sanitization: The summarization functions use regex to extract key terms but do not perform security sanitization on the inputs.
Audit Metadata