extract-wisdom

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by design, as it is instructed to process and summarize untrusted data from URLs and local files without specific boundary markers or sanitization logic.
  • Ingestion points: Content is ingested through WebFetch, mcp__youtube-transcript__get_transcript, and the Read tool for local files.
  • Boundary markers: None. The instructions do not provide delimiters or 'ignore' directives to prevent the agent from following instructions embedded within the source material.
  • Capability inventory: The skill has access to Bash, Read, WebFetch, and specialized MCP tools for transcript and web crawling.
  • Sanitization: No sanitization or validation of the ingested external content is specified in the workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 08:08 PM
Security Audit — agent-trust-hub — extract-wisdom