teamkb

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process local Markdown files and conversation session data to generate knowledge base entries.
  • Ingestion points: Files are identified using Glob and content is accessed via Read as described in SKILL.md.
  • Boundary markers: The instructions explicitly direct the agent to reject personal preferences, ephemeral steps, and content already present in READMEs.
  • Capability inventory: The skill uses mcp__teamkb__teamkb_propose and mcp__teamkb__teamkb_import to write data to local storage.
  • Sanitization: The workflow requires using Grep to scan for secret markers and necessitates a final confirmation from the user through AskUserQuestion before any batch import occurs.
  • [EXTERNAL_DOWNLOADS]: The documentation references an external GitHub repository belonging to the author for the required backend server components.
  • Evidence: https://github.com/jeremylongshore/bobs-big-brain-registrar in SKILL.md.
  • This repository provides the source code and build instructions for the MCP server used by the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 05:13 PM
Security Audit — agent-trust-hub — teamkb