contact-cache
Pass
Audited by Gen Agent Trust Hub on Mar 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted external data which could lead to indirect prompt injection. Ingestion points:
scripts/cache.py(viacmd_addand--csvflag) and CLI arguments for name and notes. Boundary markers: Absent. No delimiters are used to wrap stored data. Capability inventory: File system access to read and writecontacts.csv. Sanitization: Normalization is applied to identifiers, but no sanitization is performed on descriptive fields.
Audit Metadata