knowledge-ops
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from various external sources, creating a potential surface for indirect prompt injection attacks where malicious instructions could be embedded in ingested content.
- Ingestion points: Ingests information from GitHub issues/PRs, Linear issues, conversation exports (Claude/ChatGPT/Grok), and browser bookmarks as described in
SKILL.md. - Boundary markers: The instructions recommend using YAML frontmatter for metadata on all knowledge files to provide structure, but do not specify delimiters for external content within those files to separate user data from instructions.
- Capability inventory: The skill has capabilities to write to local memory files (
~/.claude/projects/*/memory/), commit and push to Git repositories, and invoke MCP memory tools such asmcp__memory__create_entitiesas documented inSKILL.md. - Sanitization: While the skill explicitly instructs the agent to redact sensitive data like API keys and passwords before committing to Git, it lacks specific instructions for sanitizing or escaping natural language content from external sources to prevent prompt injection.
Audit Metadata