knowledge-synthesis
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is entirely instructional and does not contain executable code, scripts, or commands that interact with the system or network.
- [PROMPT_INJECTION]: The skill is designed to process external, untrusted data (search results), which constitutes an indirect prompt injection surface. However, the risk is negligible as the skill lacks any dangerous capabilities that could be exploited via injection.
- Ingestion points: Raw results from
~~chat,~~email,~~cloud storage, and~~project trackeras defined in SKILL.md. - Boundary markers: The instructions use source-specific prefixes (e.g.,
~~chat) but do not define strict security delimiters for external content. - Capability inventory: No file system access, network operations, or subprocess execution capabilities are present in the skill.
- Sanitization: No explicit sanitization or validation of the ingested content is specified.
Audit Metadata