knowledge-schema-audit
Pass
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is a read-only auditor for project documentation and does not contain any executable scripts or binary files.
- [PROMPT_INJECTION]: The skill reads arbitrary Markdown files in the knowledge directory, creating an indirect prompt injection surface. * Ingestion points: All files matching <knowledge_dir>/**/*.md. * Boundary markers: Explicit guardrails in SKILL.md require the agent to stop if sensitive data is found and forbid inferring intent or editing files. * Capability inventory: The skill possesses no file-write or network capabilities and relies on external skills for any follow-up actions. * Sanitization: Relies on structured output definitions in references/report.md.
Audit Metadata