recallmax
Warn
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill metadata declares the author as 'christopherlhammer11-ai', which contradicts the authorized vendor context provided ('sickn33'). This mismatch in authorship is deceptive.\n- [EXTERNAL_DOWNLOADS]: The skill promotes installation using
npx skills add christopherlhammer11-ai/recallmax. This target belongs to an unverified third-party account that does not match the authorized vendor infrastructure, presenting a supply chain risk.\n- [PROMPT_INJECTION]: The skill is designed to ingest large volumes of external context (up to 1 million tokens), creating a surface for indirect prompt injection.\n - Ingestion points: SKILL.md (Context Injection section references external documents and RAG results).\n
- Boundary markers: The skill documentation does not define specific isolation delimiters or instructions for the agent to ignore embedded commands in external data.\n
- Capability inventory: The skill description includes summarization, history compression, and fact-verification capabilities.\n
- Sanitization: The documentation mentions 'clean tokens' but provides no explicit evidence of sanitization or filtering for embedded instructions in external data.
Audit Metadata