retro
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze session logs, which represent an untrusted data surface if those logs capture external inputs, compiler outputs, or web responses.
- Ingestion points: Reading primary sources and session logs from the local machine (SKILL.md, Step 2).
- Boundary markers: The instructions do not specify any delimiters or safety markers to differentiate between the agent's instructions and potentially malicious data embedded within the logs.
- Capability inventory: The skill identifies candidates for repo-level changes, including modifying
AGENTS.md(steering instructions) andCODING_STANDARDS.md(reviewer rules), which are high-leverage files for agent behavior. - Sanitization: There is no explicit sanitization or filtering logic mentioned to prevent content in the logs from being interpreted as instructions by the agent during the retrospective process.
Audit Metadata