knowledge-ops

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from various external sources, creating a potential surface for indirect prompt injection attacks where malicious instructions could be embedded in ingested content.
  • Ingestion points: Ingests information from GitHub issues/PRs, Linear issues, conversation exports (Claude/ChatGPT/Grok), and browser bookmarks as described in SKILL.md.
  • Boundary markers: The instructions recommend using YAML frontmatter for metadata on all knowledge files to provide structure, but do not specify delimiters for external content within those files to separate user data from instructions.
  • Capability inventory: The skill has capabilities to write to local memory files (~/.claude/projects/*/memory/), commit and push to Git repositories, and invoke MCP memory tools such as mcp__memory__create_entities as documented in SKILL.md.
  • Sanitization: While the skill explicitly instructs the agent to redact sensitive data like API keys and passwords before committing to Git, it lacks specific instructions for sanitizing or escaping natural language content from external sources to prevent prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:38 AM
Security Audit — agent-trust-hub — knowledge-ops