bookkeeping
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and process data from external, untrusted sources such as web clips, social media logs, and conversation transcripts. This creates a significant surface for indirect prompt injection attacks.
- Ingestion points: Content is ingested through the
ingestandruncommands inscripts/bookkeeping.py, which normalize raw sources into the entity graph. - Boundary markers: Although the skill uses structured YAML and markdown, the LLM scoring rubric and judge prompt do not include explicit 'ignore embedded instructions' warnings for the content being evaluated.
- Capability inventory: The skill has the ability to write files to the
research/directory and execute shell commands viasubprocess. A successful injection could influence which data is promoted or what shell commands are proposed during maintenance. - Sanitization: The skill performs validation of slug shapes and strips non-printable control characters (e.g., NUL bytes) to prevent filesystem corruption.
- [COMMAND_EXECUTION]: The skill utilizes
subprocess.runfor operational automation, which is an expected but powerful capability. - Evidence: Static analysis and test files (e.g.,
tests/test_render_cli.py,tests/test_temporal_revision_metadata.py) show the skill executes its own subcommands and system tools likegitvia the shell. While restricted to its intended purpose, this represents a capability that could be leveraged by an attacker if combined with an injection vulnerability. - [DYNAMIC_EXECUTION]: The skill's test infrastructure uses dynamic code loading to verify integration with other local tools.
- Evidence:
tests/test_index.pyusesimportlib.utilto dynamically load and execute local scripts (e.g.,kg.py) based on computed filesystem paths. This is limited to the local environment and intended for development testing.
Audit Metadata