knock-lifecycle-opportunities

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill scans the product codebase for business logic and events, creating a surface for indirect prompt injection where malicious instructions in the source code could potentially influence the agent's output.
  • Ingestion points: Product codebase files, specifically auth routes, models, and event triggers as defined in rules/map-product-lifecycle.md.
  • Boundary markers: Absent; there are no explicit instructions to the agent to treat the code content as non-instructional data or to ignore embedded commands.
  • Capability inventory: The skill is authorized to create and update the knock-plan.md file at the repository root.
  • Sanitization: Absent; the instructions do not specify any validation or sanitization of data extracted from the codebase before it is written to the output file.
  • [EXTERNAL_DOWNLOADS]: The skill references multiple documentation pages on knock.app and docs.knock.app. These are official resources provided by the skill vendor and are used for instructional purposes only.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 06:09 PM
Security Audit — agent-trust-hub — knock-lifecycle-opportunities