setup
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to run a local Python script (
python tools/graphify_setup.py install) to set up a knowledge graph component. Executing local scripts can perform privileged system modifications. - [INDIRECT_PROMPT_INJECTION]: The skill ingests raw user data from an interview and writes it directly to critical configuration files like
CLAUDE.md,connections.md, andcontext/files without explicit sanitization or validation. - Ingestion points: User responses provided during the setup interview in
SKILL.md(e.g., identity, business details, priorities, and voice samples). - Boundary markers: None identified; user input is directly interpolated into templates and written to persistent storage files.
- Capability inventory: The agent can perform file write operations to various system-level configuration paths and execute local Python scripts.
- Sanitization: There is no instruction to sanitize, escape, or validate the user-provided content before it is committed to files that define the agent's context and rules.
Audit Metadata