proprietary-knowledge-ingestion

Pass

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill contains only descriptive Markdown instructions and lacks any executable scripts, binaries, or platform-specific command configurations.
  • [PROMPT_INJECTION]: The skill's primary function is to ingest and act upon data from external sources (PDFs, books, courses), which introduces an indirect prompt injection attack surface.
  • Ingestion points: External private documents and workspace files referenced in SKILL.md.
  • Boundary markers: Absent; the skill does not define delimiters or instructions to prevent the agent from executing commands embedded within the ingested data.
  • Capability inventory: The logic involves reading local files, indexing them into a vector database, and prioritizing their content in generated responses.
  • Sanitization: Absent; there is no mention of filtering, escaping, or validating the content extracted from external sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 18, 2026, 05:56 PM
Security Audit — agent-trust-hub — proprietary-knowledge-ingestion