kb-retriever

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill implements a robust and resource-efficient architecture for local information retrieval, utilizing a hierarchical index structure (data_structure.md) and windowed reads (offset/limit) to minimize token consumption and prevent context overflow.- [INDIRECT_PROMPT_INJECTION]: The skill possesses a standard attack surface for indirect prompt injection as it is designed to ingest and process data from external, potentially untrusted documents.
  • Ingestion points: Files within the local knowledge base directory (Markdown, PDF, Excel).
  • Boundary markers: The skill uses progressive retrieval to limit data volume, but does not explicitly instruct the agent to ignore instructions embedded within the retrieved snippets.
  • Capability inventory: Employs shell-based tools (grep, pdftotext) and Python libraries (pandas, pdfplumber) to extract and manipulate data.
  • Sanitization: Content extracted from files is processed directly without specific sanitization filters before being returned to the agent context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:21 PM
Security Audit — agent-trust-hub — kb-retriever