knowledge-refresh-synthesis

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local Python scripts (knowledge-binding.py) and uses python3 -c for atomic JSON updates to project manifests. These operations are restricted to the local project environment and follow standard data management patterns.
  • [EXTERNAL_DOWNLOADS]: No external network operations or remote code downloads were detected. All data is sourced from the local filesystem within the designated knowledge base and wiki paths.
  • [REMOTE_CODE_EXECUTION]: There are no patterns of remote code execution or installation of untrusted dependencies. The skill purely orchestrates internal tools and scripts provided within the plugin environment.
  • [PROMPT_INJECTION]: The skill handles project identifiers and metadata. While it processes data from source pages, the risk is mitigated as it functions as an administrative tool for structured data rather than directly processing untrusted user input into high-privilege execution contexts.
  • [DATA_EXFILTRATION]: No data exfiltration patterns were identified. Access to files like binding.json and ingest-manifest.json is necessary for the skill's stated purpose of knowledge synthesis management.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 01:51 PM
Security Audit — agent-trust-hub — knowledge-refresh-synthesis