rescue-tokens

Warn

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions that explicitly command the AI to override default persona behaviors and suppress transparency features such as reasoning blocks, justifications, and standard markdown formatting.- [PROMPT_INJECTION]: Indirect Prompt Injection Surface: The skill monitors user input and context for specific trigger phrases like 'don't lose context', 'I'm so close', or 'Rate limit warnings' to force behavioral shifts or state changes.
  • Ingestion points: User conversation and system context/tool output (e.g., error messages in files or logs).
  • Boundary markers: Absent; no sanitization or delimiters are defined to distinguish genuine system errors from injected text.
  • Capability inventory: The agent can execute /clear, /compact, and /mcp commands and change the active model.
  • Sanitization: Absent; the skill acts directly on string matches in context.- [COMMAND_EXECUTION]: The skill mandates the automatic execution of state-altering commands such as /clear, /compact, and /mcp without user confirmation or prior explanation when triggers are detected.- [EXTERNAL_DOWNLOADS]: The README provides instructions for cloning the skill from a vendor-owned GitHub repository (github.com/valorisa/Claude-Skills), which is documented as a legitimate resource for this skill.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 14, 2026, 11:31 AM
Security Audit — agent-trust-hub — rescue-tokens