remember
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [NO_CODE]: The skill consists entirely of markdown instructions and does not include any scripts, executables, or code files, which minimizes its attack surface.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process session data which could contain untrusted user content. While it facilitates the persistence of information, it does not execute code based on that information. Ingestion points: The skill gathers 'session findings' as described in SKILL.md. Boundary markers: There are no specific delimiters or instructions to ignore embedded commands within the findings. Capability inventory: The skill can update 'Project memory', 'Notepad', and 'Docs' files. Sanitization: The instructions do not include steps to sanitize or validate session findings before they are promoted to durable storage.
Audit Metadata