okf-open-knowledge-format
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
SKILL.mdfile instructs the agent to check for the presence of theokflinttool and offer to install it viapiporuvif it is missing. It also includes references to the project's upstream documentation and repository on GitHub. - [COMMAND_EXECUTION]: The skill includes a bash script,
scripts/validate.sh, which uses standard utilities likefind,grep, andsedto iterate through the file system and validate the structure and frontmatter of markdown files within a bundle. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and modify user-supplied directories of markdown files to make them OKF-conformant. This creates an attack surface where malicious instructions hidden in the input files could potentially be executed or influence the agent's behavior during the enrichment process.
- Ingestion points: YAML frontmatter and markdown body content of files within the user-provided directory.
- Boundary markers: Frontmatter is delimited by triple-dashes (
---). - Capability inventory: Shell command execution via validation scripts and the ability to recommend/perform package installations.
- Sanitization: The skill lacks explicit sanitization or filtering of the content being enriched, relying on the agent to interpret and structure the data correctly.
Audit Metadata