ke
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a persistent knowledge engine that automatically ingests untrusted data from the web (via
ke research) and supplied URLs (viake learn). This content is later retrieved and injected into the agent's context during recall operations. A malicious website could include hidden instructions that, once indexed, cause the agent to deviate from its intended behavior in future sessions. - Ingestion points:
ke research(fetches web content to fill knowledge gaps) andke learn(ingests caller-supplied URLs and files). - Boundary markers: Absent; the documentation describes auto-injecting findings into matching prompts without mentioning specific delimiters or safety warnings for the agent to ignore embedded instructions.
- Capability inventory: The skill utilizes a custom binary/script (
ke), executes shell commands for job management (jq,cat), performs network operations to fetch web data, and has file system access to write to~/vault/ke/and read from arbitrary paths via@filemarkers. - Sanitization: No mention of content sanitization or filtering of ingested web content before indexing.
- [COMMAND_EXECUTION]: The skill relies on a local CLI tool (
ke) and provides several shell command patterns for the agent to execute, including background job inspection usingjqandcat, and a cache cleanup command usingfindwith the-exec rm -rfflag. While these are for management, they represent a broad execution surface. - [DATA_EXFILTRATION]: The
ke learncommand supports a@filesyntax that allows the agent to ingest local files into the searchable knowledge base. If combined with the network-fetching capabilities ofke research, there is a risk that sensitive local data could be processed and potentially exposed if the agent is tricked into ingesting private configuration files or credentials.
Audit Metadata