learn
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill fetches content from arbitrary external websites via WebSearch and WebFetch, which is a known vector for indirect prompt injection.
- Ingestion points: Data enters the agent context from external URLs through the WebFetch phase described in the 'Just-In-Time Retrieval' section of SKILL.md.
- Boundary markers: There are no explicit delimiters or 'ignore embedded instructions' warnings defined in the synthesis or extraction logic to distinguish between factual data and potential malicious instructions in the source text.
- Capability inventory: The skill has the ability to write files to the
agent-knowledge/directory, update a master index (CLAUDE.md), and execute secondary skills (enhance-docs,enhance-prompts) using the synthesized content. - Sanitization: The skill extraction process focuses on 'keyInsights' and 'codeExamples' but does not specify any sanitization, filtering, or validation of the fetched content before it is stored in the persistent knowledge base.
Audit Metadata