klimkit-walkthrough

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill includes explicit redaction rules to prevent the exposure of secrets, tokens, and sensitive customer data during the report generation process, specifically mentioning protection of tailnet internals.- [SAFE]: References to tools like klimkit-setup and klimkit-report-server are within the vendor's own namespace and align with the skill's stated purpose of managing and serving reports.- [PROMPT_INJECTION]: The skill ingests data from tasks and PRs to generate reports. While this represents a potential surface for indirect prompt injection where instructions could be embedded in the data being summarized, the risk is mitigated by the redaction instructions and the narrow scope of the reporting task.
  • Ingestion points: Task descriptions, PR content, and environment URLs (SKILL.md).
  • Boundary markers: None specified in the HTML template (references/walkthrough-report.md).
  • Capability inventory: File system writes to .klimkit/ and execution of reporting tools (SKILL.md).
  • Sanitization: Instructions require the agent to summarize sensitive material safely rather than embedding it directly.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 10:10 AM
Security Audit — agent-trust-hub — klimkit-walkthrough