knowledge-ops

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [DATA_EXFILTRATION]: The skill is designed to sync information across multiple storage layers, including external services like GitHub and Supabase. It explicitly accesses sensitive local directories such as ~/.claude/projects/*/memory/ to manage cross-session context. While it instructs the agent to redact sensitive data like API keys before committing to Git, the capability to move data between local and remote systems warrants attention.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from a wide array of untrusted external sources, which may contain malicious instructions designed to influence agent behavior.\n
  • Ingestion points: Processes documents, conversation history, GitHub issues/PRs, Linear data, and exports from other AI agents (ChatGPT, Grok, etc.) via the ingestion and sync workflows specified in SKILL.md.\n
  • Boundary markers: The skill utilizes YAML frontmatter for file metadata but lacks explicit instructions or system-level delimiters to ensure the agent disregards embedded commands in the ingested content.\n
  • Capability inventory: The skill possesses the ability to write to local files, commit and push to Git repositories, interact with MCP memory tools, and perform operations on external data stores (Supabase/PostgreSQL).\n
  • Sanitization: Instructions focus on redacting secrets (API keys, passwords) but do not specify patterns for sanitizing, escaping, or filtering potentially malicious natural language instructions within the processed data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:41 PM
Security Audit — agent-trust-hub — knowledge-ops