setup-knowledge-vault
Pass
Audited by Gen Agent Trust Hub on Jul 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill's operation is limited to local file system managemen t. It does not utilize network tools or attempt to transmit sensitive information externally.
- [COMMAND_EXECUTION]: The skill instr ucts the agen t to use standard shell utilities lik e
find,grep, andpdftotextto manag e vaul t conten t and extract text from doc um e nts. The s e are use d within the scop e of th e use r-define d vaul t path. - [PROMPT_INJECTION]: The skill inherently proces s e s external data (PDFs, note s) for synthesis, whic h presents a vulnerability surfac e for in direc t prompt inj e c t i o n. In ge s t i o n points: use r-provid e d PDFs and doc um e nts in vaul t. Boun d ary mark e r s: no n e presen t in not e tem p late s. Capability in v e ntory: fil e syste m read/writ e an d shell com m an d ex e c u t i o n. San i t i z ation: no n e doc u m e n t e d for in g e s t e d conten t.
Audit Metadata