update-knowledge-base

Pass

Audited by Gen Agent Trust Hub on Apr 2, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests and processes data from external sources.
  • Ingestion points: External content is retrieved from ticket management systems (Linear, Jira, GitHub) and provided URLs (Help Center, Changelog) via the Browser and Ticket MCPs.
  • Boundary markers: The prompt template does not use delimiters or explicit instructions to isolate external data from its primary instructions, meaning malicious text within a ticket could potentially influence the agent's behavior.
  • Capability inventory: The agent has permissions to read and write files in Google Drive and interact with ticket systems and browser tools.
  • Sanitization: There is no evidence of sanitization or validation performed on the external content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 2, 2026, 08:18 PM
Security Audit — agent-trust-hub — update-knowledge-base