buildbetter-knowledge-gaps
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or unauthorized access attempts were found. The skill follows security best practices by enforcing human-in-the-loop validation for all state-changing operations.
- [INDIRECT_PROMPT_INJECTION]: The skill operates on external data describing knowledge gaps and release sources, creating a potential surface for indirect injection. 1. Ingestion points: Data is ingested into the agent context via tools like list-knowledge-gaps and sync-release-sources (SKILL.md). 2. Boundary markers: The instructions explicitly mandate that the agent must obtain approval and read back the exact gap ID before performing any mutations. 3. Capability inventory: The skill possesses capabilities to modify gap states, attach gaps to projects, and execute release analysis tasks. 4. Sanitization: No specific technical sanitization of external content is described; however, the human-in-the-loop approval requirement serves as a robust behavioral control.
Audit Metadata