retro
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from coding session logs (SKILL.md, Step 2).
- Ingestion points: Session logs searched and read as defined in SKILL.md.
- Boundary markers: The instructions do not define delimiters or specific 'ignore' instructions for the ingested log content.
- Capability inventory: The skill is restricted by its instructions to reading logs and presenting findings to the user; it lacks capabilities for network access, arbitrary command execution, or file writing.
- Sanitization: No validation or sanitization of the log data is performed prior to processing.
- The risk is minimal as the skill only generates suggestions for user review and does not take automated actions.
Audit Metadata