kb-summarization

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface due to its primary function of processing user-generated knowledge content.
  • Ingestion points: Untrusted content is ingested from the kb_knowledge table (text and wiki fields) and associated sys_attachment records as seen in the retrieval procedure.
  • Boundary markers: The summarization process lacks defined boundary markers or system instructions to ignore potential instructions embedded within the article text.
  • Capability inventory: The skill has access to the SN-Update-Record tool, allowing it to modify records in the ServiceNow instance, and requests access to the Bash native tool.
  • Sanitization: There is no evidence of content sanitization or instruction filtering applied to the retrieved article content before it is processed by the model.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 01:35 PM
Security Audit — agent-trust-hub — kb-summarization