skills/broomva/skills/kg/Gen Agent Trust Hub

kg

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests entity bodies from local markdown files (research/entities/**/*.md) and interpolates them into the agent's context for reasoning.
  • Ingestion points: scripts/kg.py reads entity file content using Path.read_text() to construct the context block.
  • Boundary markers: The render_load_output function uses bordered ASCII blocks to separate entity contents, providing basic structural delimitation.
  • Capability inventory: The skill enables file system reads and writes (via the "binding reflex" instruction) and execution of the local kg.py script.
  • Sanitization: The skill performs no explicit filtering or sanitization for prompt injection instructions embedded within the ingested markdown bodies.
  • [COMMAND_EXECUTION]: The instructions in SKILL.md direct the agent to execute multiple shell commands including ls, head, and python3 to manage the catalog and load knowledge data.
  • Evidence: Multiple code blocks in SKILL.md provide bash commands for manual catalog verification and script execution.
  • [DYNAMIC_EXECUTION]: The test script uses dynamic module loading to import the main script for validation.
  • Evidence: scripts/test_kg.py uses importlib.util.spec_from_file_location to load kg.py from the filesystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 03:09 PM
Security Audit — agent-trust-hub — kg