brain

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests snippets from an external corpus via the teamkb_search tool, which creates a surface for indirect prompt injection where malicious content in the indexed documents could influence the agent's behavior.
  • Ingestion points: Snippets and retrieval metadata returned by the mcp__teamkb__teamkb_search tool.
  • Boundary markers: The instructions do not specify the use of clear delimiters or explicit instructions for the agent to ignore potential commands embedded within the search results.
  • Capability inventory: The skill is granted access to the mcp__teamkb__teamkb_search tool for read-only retrieval from the team knowledge base.
  • Sanitization: There are no defined steps for filtering, sanitizing, or validating the content retrieved from the external source before synthesis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 05:14 PM
Security Audit — agent-trust-hub — brain