steward
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local script at
scripts/graph-auditto validate the integrity of the knowledge vault during mutation cycles.\n- [DATA_EXFILTRATION]: The skill accesses a shared configuration file at../../CONVENTIONS.mdrelative to the skill directory, which involves reading content outside the skill's specific installation root.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from theraw/inbox/directory, presenting a surface for indirect prompt injection attacks.\n - Ingestion points: External source files and pasted content in the
raw/inbox/folder are read for processing.\n - Boundary markers: No explicit technical delimiters are present for input content; relies on procedural manual reviews with the user.\n
- Capability inventory: Subprocess execution for validation and write access to vault pages, indexes, and ledger files.\n
- Sanitization: Uses human-in-the-loop diff approvals and confidence tagging, but lacks automated text sanitization.
Audit Metadata