knowledge-synthesis

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • Indirect Prompt Injection Surface: The skill's primary function is to process and synthesize data from external, potentially untrusted sources such as chat logs, emails, and shared documents. This creates a surface where malicious instructions embedded in that data could influence the agent's behavior during the synthesis process.
  • Ingestion points: As described in SKILL.md, the skill ingests "raw results" from chat, email, cloud storage, and project management tools.
  • Boundary markers: The synthesis guidelines do not currently specify the use of clear delimiters or instructions for the agent to treat result content strictly as data, which is a common practice to mitigate injection risks.
  • Capability inventory: This skill file contains no executable code or tool definitions; however, the synthesis logic it defines is intended to guide an agent that likely possesses various search and reporting capabilities.
  • Sanitization: The skill does not provide specific instructions for sanitizing, filtering, or validating the text content gathered from external sources before it is processed.
  • Instructional Content Only: The skill is composed entirely of markdown documentation and YAML configuration. It does not ship with executable scripts, binaries, or remote dependencies, which minimizes the risk of direct command execution or persistence.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:46 PM
Security Audit — agent-trust-hub — knowledge-synthesis