beachhead-segment
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests user-supplied evidence and segment descriptions to generate recommendations that are stored in the workspace, creating a potential vector for data-driven instruction influence.
- Ingestion points: User input in Step 1 (segments and evidence) and Step 0 (Quick-Brain responses). File reads from /foundation/brain.md and /context/meta-patterns.md.
- Boundary markers: No specific delimiters or safety instructions are used to separate ingested data from agent instructions during interpolation.
- Capability inventory: File-write access to /foundation/brain.md (Steps 0 and 5) and /context/skill-sessions.md (Step 6).
- Sanitization: The skill lacks documented procedures for filtering or validating external input before processing or writing to files.
- [DATA_EXPOSURE_EXFILTRATION]: The skill accesses and writes to organizational context files to maintain business strategy state.
- Evidence: Reads from /foundation/brain.md and /context/meta-patterns.md. Writes to /foundation/brain.md and /context/skill-sessions.md. These operations are restricted to the local workspace and do not involve network transmission or access to system-level credentials.
Audit Metadata