knowledge-base-manager
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a workflow for ingesting untrusted data from external sources and processing it using an LLM, creating a vulnerability surface for indirect prompt injection.
- Ingestion points: The
ingestDocumentandcheckSourceFreshnessfunctions (found inreferences/curation.md) ingest content from raw documents and remote URLs. - Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are present in the processing logic.
- Capability inventory: The skill utilizes network operations (
fetch) to retrieve content and passes data to an LLM via theautoTagfunction. - Sanitization: While basic cleaning functions like
stripHtmlandnormalizeMarkdownare implemented, they are designed for formatting rather than security-focused sanitization against adversarial inputs. - [EXTERNAL_DOWNLOADS]: The skill contains reference code for fetching content from external URLs to perform freshness checks and content ingestion.
- Evidence: The
checkSourceFreshnessfunction inreferences/curation.mduses thefetchAPI to perform HEAD and GET requests on external URLs provided inSourceRecordobjects.
Audit Metadata