knock-lifecycle-opportunities
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill scans the product codebase for business logic and events, creating a surface for indirect prompt injection where malicious instructions in the source code could potentially influence the agent's output.
- Ingestion points: Product codebase files, specifically auth routes, models, and event triggers as defined in
rules/map-product-lifecycle.md. - Boundary markers: Absent; there are no explicit instructions to the agent to treat the code content as non-instructional data or to ignore embedded commands.
- Capability inventory: The skill is authorized to create and update the
knock-plan.mdfile at the repository root. - Sanitization: Absent; the instructions do not specify any validation or sanitization of data extracted from the codebase before it is written to the output file.
- [EXTERNAL_DOWNLOADS]: The skill references multiple documentation pages on
knock.appanddocs.knock.app. These are official resources provided by the skill vendor and are used for instructional purposes only.
Audit Metadata