reflect

Pass

Audited by Gen Agent Trust Hub on Apr 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, data exfiltration attempts, or unauthorized external communications were detected.
  • [COMMAND_EXECUTION]: The skill instructs the agent to use date for time calculations and find for locating local markdown files in the sessions/ directory. These are routine operations for managing local state.
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it processes untrusted data from local files.
  • Ingestion points: Markdown files located in the sessions/ directory (SKILL.md).
  • Boundary markers: No delimiters or instructions are used to separate ingested file content from the agent's instructions.
  • Capability inventory: The agent can execute find and date commands, read local session files, and write reflections to the reflections/ directory (SKILL.md).
  • Sanitization: There is no evidence of content sanitization or validation of the processed files.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 4, 2026, 03:04 PM