graph-ingest

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources, creating an attack surface for indirect prompt injection where malicious content could influence the agent's behavior. * Ingestion points: External data is fetched into the git-ignored raw/ directory via the graphify add command (SKILL.md). * Boundary markers: The instructions lack explicit delimitation or boundary markers to separate external content from instructions during the wiki admission phase. * Capability inventory: The skill performs network requests to fetch content, writes files to the wiki directory, and executes the local tools/wiki_lint.py script (SKILL.md). * Sanitization: The process requires manual de-identification of PII/PHI and uses a linting tool (tools/wiki_lint.py) to scan for secrets and broken links before data is committed.
  • [EXTERNAL_DOWNLOADS]: The skill fetches content from arbitrary user-provided URLs such as papers, blog posts, and tweets for processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 07:20 PM
Security Audit — agent-trust-hub — graph-ingest