kb-retriever
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill implements a robust and resource-efficient architecture for local information retrieval, utilizing a hierarchical index structure (data_structure.md) and windowed reads (offset/limit) to minimize token consumption and prevent context overflow.- [INDIRECT_PROMPT_INJECTION]: The skill possesses a standard attack surface for indirect prompt injection as it is designed to ingest and process data from external, potentially untrusted documents.
- Ingestion points: Files within the local knowledge base directory (Markdown, PDF, Excel).
- Boundary markers: The skill uses progressive retrieval to limit data volume, but does not explicitly instruct the agent to ignore instructions embedded within the retrieved snippets.
- Capability inventory: Employs shell-based tools (grep, pdftotext) and Python libraries (pandas, pdfplumber) to extract and manipulate data.
- Sanitization: Content extracted from files is processed directly without specific sanitization filters before being returned to the agent context.
Audit Metadata