skills/kkenny0/loom-skills/deep-read/Gen Agent Trust Hub

deep-read

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its document processing nature. \n
  • Ingestion points: External data is ingested in Workflows/01-capture.md via mcp__web-reader__webReader (URLs) and the Read tool (PDFs and local files). \n
  • Boundary markers: Absent. In Workflows/02-read.md, untrusted content is passed directly to background agents using the template {素材全文或关键段落} without delimiters or instructions to ignore embedded instructions. \n
  • Capability inventory: The skill uses Read, Write, and WebSearch tools, allowing for file system interaction and network access based on processed content. \n
  • Sanitization: No escaping or filtering of external content is specified before interpolation into prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 12:36 PM
Security Audit — agent-trust-hub — deep-read