compile-knowledge

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill involves reading and updating existing markdown files in the memory or wiki storage, which represents an indirect prompt injection surface. Malicious content previously stored in these files could potentially influence the agent when retrieved.\n
  • Ingestion points: The agent reads from .claude/.../memory/ and wiki/ directories to search for existing topics (SKILL.md).\n
  • Boundary markers: No specific boundary markers or 'ignore' instructions are mandated for the content of the knowledge files.\n
  • Capability inventory: The skill allows for file writing/editing and the execution of the 5dive CLI tools.\n
  • Sanitization: The procedure does not include explicit sanitization or validation of the content being read or written to the store.\n- [COMMAND_EXECUTION]: The skill mentions the use of the 5dive CLI (e.g., 5dive memory consolidate, 5dive memory add) for managing the persistence layer. These commands are associated with the vendor's (5dive-ai) environment and support the primary function of the skill.\n- [NO_CODE]: This skill consists entirely of markdown instructions and documentation without accompanying scripts or executable files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:01 AM
Security Audit — agent-trust-hub — compile-knowledge