knowledge-gap-map

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill is comprised entirely of natural language instructions for the agent to follow during a conversation. It does not include any scripts, commands, or system calls that could pose a security threat.
  • [NO_CODE]: Analysis confirms the absence of Python or Node.js packages, build scripts, or remote code execution patterns.
  • [INDIRECT_PROMPT_INJECTION]: Surface identified: (1) Ingestion points: The skill processes user-supplied inputs for 'subject', 'goal', and 'knowledge' within SKILL.md. (2) Boundary markers: No explicit delimiters or safety warnings for user input are provided. (3) Capability inventory: None; the skill lacks tools, network access, or file-write capabilities. (4) Sanitization: Not applicable as no downstream tools are used. The lack of capabilities ensures that any potential injection in the data cannot be executed or cause harm.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 05:56 PM
Security Audit — agent-trust-hub — knowledge-gap-map