knowledge-capture

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized operations were detected.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it processes user-supplied notes. 1. Ingestion points: Material is read from member workspaces and conversation summaries (SKILL.md). 2. Boundary markers: No explicit delimiter markers are used for untrusted data. 3. Capability inventory: The skill has the capability to write files to the project knowledge directory (SKILL.md). 4. Sanitization: It instructs the agent to filter out command chatter and private notes. The risk is significantly reduced by a mandatory dry-run review before any files are written.
  • [DATA_EXFILTRATION]: The skill includes guardrails preventing the storage of secrets, credentials, or private data, and lacks network capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 05:11 AM
Security Audit — agent-trust-hub — knowledge-capture