kb-summarization
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface due to its primary function of processing user-generated knowledge content.
- Ingestion points: Untrusted content is ingested from the
kb_knowledgetable (textandwikifields) and associatedsys_attachmentrecords as seen in the retrieval procedure. - Boundary markers: The summarization process lacks defined boundary markers or system instructions to ignore potential instructions embedded within the article text.
- Capability inventory: The skill has access to the
SN-Update-Recordtool, allowing it to modify records in the ServiceNow instance, and requests access to theBashnative tool. - Sanitization: There is no evidence of content sanitization or instruction filtering applied to the retrieved article content before it is processed by the model.
Audit Metadata