retro

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from coding session logs (SKILL.md, Step 2).
  • Ingestion points: Session logs searched and read as defined in SKILL.md.
  • Boundary markers: The instructions do not define delimiters or specific 'ignore' instructions for the ingested log content.
  • Capability inventory: The skill is restricted by its instructions to reading logs and presenting findings to the user; it lacks capabilities for network access, arbitrary command execution, or file writing.
  • Sanitization: No validation or sanitization of the log data is performed prior to processing.
  • The risk is minimal as the skill only generates suggestions for user review and does not take automated actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:48 AM
Security Audit — agent-trust-hub — retro