knowledge-intake

Pass

Audited by Gen Agent Trust Hub on May 11, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest and process untrusted content from web URLs and various file formats (PDF, Word, etc.). To mitigate the risk of indirect prompt injection, it explicitly instructs the use of content boundary markers and automated safety scans via the scribe:slop-detector. These procedures ensure external data is treated as information rather than instructions for the agent.
  • [COMMAND_EXECUTION]: The skill leverages standard developer tools, including the gh CLI for creating GitHub Discussions and local Python scripts for corpus maintenance. These operations are essential to the stated purpose of the skill and are guarded by human-in-the-loop confirmation requirements for sensitive actions.
Audit Metadata
Risk Level
SAFE
Analyzed
May 11, 2026, 08:19 AM