knowledge-ops
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [DATA_EXFILTRATION]: The skill is designed to sync information across multiple storage layers, including external services like GitHub and Supabase. It explicitly accesses sensitive local directories such as
~/.claude/projects/*/memory/to manage cross-session context. While it instructs the agent to redact sensitive data like API keys before committing to Git, the capability to move data between local and remote systems warrants attention.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from a wide array of untrusted external sources, which may contain malicious instructions designed to influence agent behavior.\n - Ingestion points: Processes documents, conversation history, GitHub issues/PRs, Linear data, and exports from other AI agents (ChatGPT, Grok, etc.) via the ingestion and sync workflows specified in SKILL.md.\n
- Boundary markers: The skill utilizes YAML frontmatter for file metadata but lacks explicit instructions or system-level delimiters to ensure the agent disregards embedded commands in the ingested content.\n
- Capability inventory: The skill possesses the ability to write to local files, commit and push to Git repositories, interact with MCP memory tools, and perform operations on external data stores (Supabase/PostgreSQL).\n
- Sanitization: Instructions focus on redacting secrets (API keys, passwords) but do not specify patterns for sanitizing, escaping, or filtering potentially malicious natural language instructions within the processed data.
Audit Metadata