skills/bosens-china/loci/use-loci/Gen Agent Trust Hub

use-loci

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill is designed to interact with external network resources to fetch technical documentation via tools like loci_pull_cloud_library and loci_add_library. This involves downloading content from user-specified or cloud-discovered URLs to populate a local documentation database.- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface (Category 8) because it processes untrusted documentation content from the web. 1. Ingestion points: Technical documentation content is ingested from external URLs via loci_read_files and loci_search_files. 2. Boundary markers: The skill instructs the agent to distinguish between documented facts and its own inferences, though no cryptographic or physical isolation is present. 3. Capability inventory: The agent can perform network reads and local database writes through the Loci MCP interface. 4. Sanitization: The instructions explicitly forbid the agent from attempting to handle cookies, tokens, credentials, or Cloudflare bypass mechanisms when accessing documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 12:27 PM
Security Audit — agent-trust-hub — use-loci