kg
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests entity bodies from local markdown files (
research/entities/**/*.md) and interpolates them into the agent's context for reasoning. - Ingestion points:
scripts/kg.pyreads entity file content usingPath.read_text()to construct the context block. - Boundary markers: The
render_load_outputfunction uses bordered ASCII blocks to separate entity contents, providing basic structural delimitation. - Capability inventory: The skill enables file system reads and writes (via the "binding reflex" instruction) and execution of the local
kg.pyscript. - Sanitization: The skill performs no explicit filtering or sanitization for prompt injection instructions embedded within the ingested markdown bodies.
- [COMMAND_EXECUTION]: The instructions in
SKILL.mddirect the agent to execute multiple shell commands includingls,head, andpython3to manage the catalog and load knowledge data. - Evidence: Multiple code blocks in
SKILL.mdprovide bash commands for manual catalog verification and script execution. - [DYNAMIC_EXECUTION]: The test script uses dynamic module loading to import the main script for validation.
- Evidence:
scripts/test_kg.pyusesimportlib.util.spec_from_file_locationto loadkg.pyfrom the filesystem.
Audit Metadata