kb-librarian

Warn

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes python3 to run a script located at ~/.claude/scripts/kb-index.py. It explicitly instructs the agent to pass user input directly into the --query argument: python3 ~/.claude/scripts/kb-index.py --query "用户问题". This pattern is susceptible to command injection if the user-supplied query contains shell metacharacters such as semicolons, pipes, or backticks.
  • [INDIRECT_PROMPT_INJECTION]: This skill provides a surface for indirect prompt injection by ingesting and storing content from external URLs and raw text.
  • Ingestion points: Content is extracted from user-supplied URLs or text and saved to the raw/ and sources/ directories within the skill's workspace.
  • Boundary markers: The skill lacks defined delimiters or specific instructions to ignore embedded instructions when saving or reading these files.
  • Capability inventory: The agent has the capability to execute local shell commands via python3 and perform filesystem writes across multiple directories (raw/, sources/, concepts/, maps/, _index/).
  • Sanitization: There are no instructions provided for sanitizing, escaping, or validating the ingested external data before it is re-integrated into the agent's context during the 'Compile' or 'Query' phases.
  • [DATA_EXPOSURE]: The skill interacts with and executes scripts from the ~/.claude/ directory. This is a sensitive location typically used for agent configuration and internal scripts, and unauthorized interaction with this path could lead to the exposure or manipulation of agent internals.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 15, 2026, 03:23 AM
Security Audit — agent-trust-hub — kb-librarian