retro
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes session logs and repository-specific configuration files (such as
package.jsonand CI workflows) to generate suggestions. This data ingestion surface is susceptible to indirect prompt injection if the logs or files contain maliciously crafted instructions designed to influence the agent's retrospective analysis. - Ingestion points: Session logs and repository files (e.g.,
package.json, CI configs) referenced inSKILL.md. - Boundary markers: The instructions do not specify the use of delimiters or 'ignore' directives to separate untrusted log content from the skill's logic.
- Capability inventory: The skill can invoke other skills (e.g.,
writing-for-agents) and perform broad filesystem reads to locate logs and configuration files. - Sanitization: No sanitization, validation, or filtering of the ingested log data is described.
Audit Metadata