keep-recon
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
find,grep, andxargsto scan the local filesystem for customer success artifacts, email lifecycle templates, and health metrics. These operations are restricted to searching for patterns within specific file types (.tsx, .jsx, .vue, .ts, .json, .md). - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it reads and processes the contents of local files to generate its assessment.
- Ingestion points: Local source code and documentation files scanned in Step 0 of SKILL.md.
- Boundary markers: None. Content is directly grep-ed and presented to the model for analysis.
- Capability inventory: Bash, WebFetch, WebSearch, and AskUserQuestion.
- Sanitization: None. The skill assumes the integrity of the files it searches.
Audit Metadata