save
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE] (SAFE): No malicious patterns or security risks were identified. The skill instructions focus on analyzing session progress and using internal MCP tools like
write_memoryandlist_memoriesto store context. - [PROMPT_INJECTION] (SAFE): The skill contains an indirect prompt injection surface (Category 8) due to its core functionality of reading and summarizing session files. Ingestion points: Project files modified during the session and existing memories via
read_memory. Boundary markers: Absent. The skill does not define delimiters for the content it summarizes. Capability inventory: Limited to MCP memory tools (list_memories,read_memory,write_memory). No shell, network, or filesystem-write capabilities are present. Sanitization: Absent. This surface is considered safe as the capabilities are restricted to state management.
Audit Metadata