setup-knowledge-vault

Pass

Audited by Gen Agent Trust Hub on Jul 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill's operation is limited to local file system managemen t. It does not utilize network tools or attempt to transmit sensitive information externally.
  • [COMMAND_EXECUTION]: The skill instr ucts the agen t to use standard shell utilities lik e find, grep, and pdftotext to manag e vaul t conten t and extract text from doc um e nts. The s e are use d within the scop e of th e use r-define d vaul t path.
  • [PROMPT_INJECTION]: The skill inherently proces s e s external data (PDFs, note s) for synthesis, whic h presents a vulnerability surfac e for in direc t prompt inj e c t i o n. In ge s t i o n points: use r-provid e d PDFs and doc um e nts in vaul t. Boun d ary mark e r s: no n e presen t in not e tem p late s. Capability in v e ntory: fil e syste m read/writ e an d shell com m an d ex e c u t i o n. San i t i z ation: no n e doc u m e n t e d for in g e s t e d conten t.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 12, 2026, 11:17 AM
Security Audit — agent-trust-hub — setup-knowledge-vault