knowledge-intake
Pass
Audited by Gen Agent Trust Hub on May 11, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and process untrusted content from web URLs and various file formats (PDF, Word, etc.). To mitigate the risk of indirect prompt injection, it explicitly instructs the use of content boundary markers and automated safety scans via the
scribe:slop-detector. These procedures ensure external data is treated as information rather than instructions for the agent. - [COMMAND_EXECUTION]: The skill leverages standard developer tools, including the
ghCLI for creating GitHub Discussions and local Python scripts for corpus maintenance. These operations are essential to the stated purpose of the skill and are guarded by human-in-the-loop confirmation requirements for sensitive actions.
Audit Metadata