knowledge-synthesis

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is entirely instructional and does not contain executable code, scripts, or commands that interact with the system or network.
  • [PROMPT_INJECTION]: The skill is designed to process external, untrusted data (search results), which constitutes an indirect prompt injection surface. However, the risk is negligible as the skill lacks any dangerous capabilities that could be exploited via injection.
  • Ingestion points: Raw results from ~~chat, ~~email, ~~cloud storage, and ~~project tracker as defined in SKILL.md.
  • Boundary markers: The instructions use source-specific prefixes (e.g., ~~chat) but do not define strict security delimiters for external content.
  • Capability inventory: No file system access, network operations, or subprocess execution capabilities are present in the skill.
  • Sanitization: No explicit sanitization or validation of the ingested content is specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 12:22 PM
Security Audit — agent-trust-hub — knowledge-synthesis