kb-health
Pass
Audited by Gen Agent Trust Hub on Apr 9, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local Python scripts (
lint_obsidian_mechanics.pyandbuild_governance_indices.py) located in a sibling directory (../obsidian-notes-karpathy/scripts/) to automate linting and governance indexing tasks. - [PROMPT_INJECTION]: The skill processes content from various sources such as
wiki/live/andoutputs/qa/(ingestion points) which may contain untrusted instructions. It lacks explicit boundary markers or sanitization logic. The skill maintains capabilities for file modification and command execution (capability inventory), which could be targets for indirect injection attacks.
Audit Metadata