starworkKnowledge

Pass

Audited by Gen Agent Trust Hub on Jun 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the starwork CLI tool to perform project-level tasks including initialization (init), status monitoring (status), and structure validation (check). These operations are scoped to the local environment and require explicit user flags for state-changing actions.
  • [PROMPT_INJECTION]: The skill is designed to process and summarize external documents (PDFs, transcripts, meeting notes), which creates a surface for indirect prompt injection.
  • Ingestion points: User-provided materials, schema.md, and index.md are ingested into the agent context (SKILL.md).
  • Boundary markers: The skill implements a strict "Incoming Material Classification" workflow and a mandatory "Preview before write" table to prevent automatic obedience to embedded instructions.
  • Capability inventory: The skill can execute starwork CLI commands and write to local project directories (pages/, synthesis/, sources/).
  • Sanitization: The skill relies on human-in-the-loop (HITL) confirmation and manual classification to validate content before persistence.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 27, 2026, 10:30 PM
Security Audit — agent-trust-hub — starworkKnowledge