zk-steward

Pass

Audited by Gen Agent Trust Hub on Mar 11, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest and process external data (e.g., books, long videos, and articles) to create structured atomic notes and logic trees. This creates an attack surface for indirect prompt injection, where instructions hidden within the analyzed content could influence the agent's behavior. * Ingestion points: Deep-reading tasks for books, videos, papers, and articles mentioned in the companion skills section. * Boundary markers: The skill lacks explicit delimiters or instructions to ignore embedded commands within the processed text. * Capability inventory: The agent is authorized to perform file-write operations (creating notes, daily logs, and index entries) and sync data to persistent memory files. * Sanitization: No sanitization or validation of external content is specified before incorporation into the knowledge network.
  • [EXTERNAL_DOWNLOADS]: The skill documentation references and encourages the use of external repositories (github.com/msitarzewski/agency-agents and github.com/mikonos/zk-steward-companion) for its source code and companion capabilities. These repositories are not affiliated with the stated author (Dev-Dennis-040) and are not included in the trusted vendors list. Suggesting that users download and execute scripts from these unverified third-party sources presents a potential supply chain risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 11, 2026, 09:44 AM
Security Audit — agent-trust-hub — zk-steward