buildbetter-knowledge-gaps

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized access attempts were found. The skill follows security best practices by enforcing human-in-the-loop validation for all state-changing operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates on external data describing knowledge gaps and release sources, creating a potential surface for indirect injection. 1. Ingestion points: Data is ingested into the agent context via tools like list-knowledge-gaps and sync-release-sources (SKILL.md). 2. Boundary markers: The instructions explicitly mandate that the agent must obtain approval and read back the exact gap ID before performing any mutations. 3. Capability inventory: The skill possesses capabilities to modify gap states, attach gaps to projects, and execute release analysis tasks. 4. Sanitization: No specific technical sanitization of external content is described; however, the human-in-the-loop approval requirement serves as a robust behavioral control.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 05:47 PM
Security Audit — agent-trust-hub — buildbetter-knowledge-gaps