traceknot
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted repository content, including requirements, issues, and instructions. It incorporates explicit defensive guidelines for the agent, instructing it to treat this third-party content as untrusted evidence and to extract facts without following any embedded prompts or arbitrary commands found within the data.- [COMMAND_EXECUTION]: The skill utilizes a bundled binary executable,
traceknot, to perform QA verification, self-checks, and report publication. The instructions guide the agent to invoke this binary from the local skill installation directory to ensure the integrity of the execution environment.- [EXTERNAL_DOWNLOADS]: The documentation includes standard commands for installing and updating the skill bundle using thenpx skillsCLI. These commands target the author's official repository and are part of the normal lifecycle management for the skill.
Audit Metadata