create-context

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes external data (codebase entities, types, and database tables) to propose domain terms. This creates a surface for indirect prompt injection if an attacker embeds malicious instructions within the source code files.
  • Ingestion points: The Phase 1: explore step instructions the agent to read arbitrary codebase files to find raw material.
  • Boundary markers: The skill implements a human-in-the-loop validation, requiring user confirmation for every term and definition before writing to the filesystem.
  • Capability inventory: The skill utilizes file-read operations across the codebase and file-write operations specifically for CONTEXT.md and related context files.
  • Sanitization: No explicit code-level sanitization is performed on the ingested strings; however, the iterative Q&A process acts as a functional filter for anomalous or malicious content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 12:02 AM
Security Audit — agent-trust-hub — create-context