aidlc-knowledge

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data in the form of customer-provided documents (PDFs, Word, Markdown) and filenames. It proactively mitigates this risk by providing the agent with mandatory instructions to treat document content, summaries, and filenames as data only, never as imperatives or instructions. The skill design includes inline boundary markers (e.g., content_notice, path_notice) that are served with the data to ensure the agent maintains a clear distinction between system instructions and untrusted content.
  • [COMMAND_EXECUTION]: The skill executes a localized tool script (aidlc-knowledge.ts) via bun for document management tasks. These operations are restricted to the local workspace and intended for cataloging, syncing, and summarizing document metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 07:24 PM
Security Audit — agent-trust-hub — aidlc-knowledge