ktx-ai-data-agents-mcp-context-skills

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the @kaelio/ktx package via NPM and cloning of its source code from GitHub. These resources are from the official repositories of the tool being configured and are used for its core functionality.
  • [COMMAND_EXECUTION]: Provides instructions for executing numerous CLI commands (ktx setup, ktx ingest, ktx mcp start) to manage project state, ingest metadata, and start an MCP server. These commands are standard for the described tool's operation.
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests data from external sources (Notion, company wikis, dbt documentation) to provide context to the agent. This surface is expected given the skill's purpose as an executable context layer.
  • Ingestion points: Processes data from Notion API, local markdown documents, and dbt artifacts (manifest.json, catalog.json).
  • Boundary markers: No explicit delimiters are specified in the documentation to isolate ingested content from agent instructions.
  • Capability inventory: Agent capabilities include searching semantic layers, retrieving metric definitions, and performing database queries through the MCP interface.
  • Sanitization: No explicit sanitization or filtering of external source content is documented.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 10:20 AM
Security Audit — agent-trust-hub — ktx-ai-data-agents-mcp-context-skills