kb-render
Pass
Audited by Gen Agent Trust Hub on Apr 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes content from multiple external reference files without boundary markers or sanitization, creating an indirect prompt injection surface. Ingestion points: Local files AGENTS.md and CLAUDE.md, and several reference files in the sibling directory ../obsidian-notes-karpathy/. Boundary markers: Content is read directly as grounding sources with no delimiters or instructions to ignore embedded commands. Capability inventory: Potential execution of render_live_artifact.py. Sanitization: No validation or filtering of ingested file content is specified.
- [COMMAND_EXECUTION]: The skill directs the agent to execute a local Python script named render_live_artifact.py if available, which constitutes direct command execution on the host environment.
Audit Metadata