kb-librarian
Warn
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes
python3to run a script located at~/.claude/scripts/kb-index.py. It explicitly instructs the agent to pass user input directly into the--queryargument:python3 ~/.claude/scripts/kb-index.py --query "用户问题". This pattern is susceptible to command injection if the user-supplied query contains shell metacharacters such as semicolons, pipes, or backticks. - [INDIRECT_PROMPT_INJECTION]: This skill provides a surface for indirect prompt injection by ingesting and storing content from external URLs and raw text.
- Ingestion points: Content is extracted from user-supplied URLs or text and saved to the
raw/andsources/directories within the skill's workspace. - Boundary markers: The skill lacks defined delimiters or specific instructions to ignore embedded instructions when saving or reading these files.
- Capability inventory: The agent has the capability to execute local shell commands via
python3and perform filesystem writes across multiple directories (raw/,sources/,concepts/,maps/,_index/). - Sanitization: There are no instructions provided for sanitizing, escaping, or validating the ingested external data before it is re-integrated into the agent's context during the 'Compile' or 'Query' phases.
- [DATA_EXPOSURE]: The skill interacts with and executes scripts from the
~/.claude/directory. This is a sensitive location typically used for agent configuration and internal scripts, and unauthorized interaction with this path could lead to the exposure or manipulation of agent internals.
Audit Metadata