update-knowledge-base
Pass
Audited by Gen Agent Trust Hub on Apr 2, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests and processes data from external sources.
- Ingestion points: External content is retrieved from ticket management systems (Linear, Jira, GitHub) and provided URLs (Help Center, Changelog) via the Browser and Ticket MCPs.
- Boundary markers: The prompt template does not use delimiters or explicit instructions to isolate external data from its primary instructions, meaning malicious text within a ticket could potentially influence the agent's behavior.
- Capability inventory: The agent has permissions to read and write files in Google Drive and interact with ticket systems and browser tools.
- Sanitization: There is no evidence of sanitization or validation performed on the external content before it is processed by the agent.
Audit Metadata