skills/a-canary/arc-skills/ke/Gen Agent Trust Hub

ke

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a persistent knowledge engine that automatically ingests untrusted data from the web (via ke research) and supplied URLs (via ke learn). This content is later retrieved and injected into the agent's context during recall operations. A malicious website could include hidden instructions that, once indexed, cause the agent to deviate from its intended behavior in future sessions.
  • Ingestion points: ke research (fetches web content to fill knowledge gaps) and ke learn (ingests caller-supplied URLs and files).
  • Boundary markers: Absent; the documentation describes auto-injecting findings into matching prompts without mentioning specific delimiters or safety warnings for the agent to ignore embedded instructions.
  • Capability inventory: The skill utilizes a custom binary/script (ke), executes shell commands for job management (jq, cat), performs network operations to fetch web data, and has file system access to write to ~/vault/ke/ and read from arbitrary paths via @file markers.
  • Sanitization: No mention of content sanitization or filtering of ingested web content before indexing.
  • [COMMAND_EXECUTION]: The skill relies on a local CLI tool (ke) and provides several shell command patterns for the agent to execute, including background job inspection using jq and cat, and a cache cleanup command using find with the -exec rm -rf flag. While these are for management, they represent a broad execution surface.
  • [DATA_EXFILTRATION]: The ke learn command supports a @file syntax that allows the agent to ingest local files into the searchable knowledge base. If combined with the network-fetching capabilities of ke research, there is a risk that sensitive local data could be processed and potentially exposed if the agent is tricked into ingesting private configuration files or credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 08:52 PM
Security Audit — agent-trust-hub — ke