conversation-archaeologist

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection (LOW): The skill is designed to ingest and summarize large volumes of untrusted historical data using the conversation_search and recent_chats tools.
  • Ingestion points: Historical chat logs and past conversations extracted via search tools.
  • Boundary markers: Absent. The instructions do not provide delimiters or warnings to ignore instructions that might be embedded in the mined text.
  • Capability inventory: The resulting 'User Manual' is intended to 'make all other skills smarter,' meaning the output directly influences the system prompt or context of future agent interactions.
  • Sanitization: Absent. There is no mechanism to filter out malicious patterns, legacy jailbreaks, or instructions contained within the historical data being processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:38 PM