executorch-kb
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- External Documentation Fetching: The skill includes instructions to fetch technical specifications and operator support details from external sources. These sources include official documentation from Qualcomm, Apple, Arm, and Google (XNNPACK). This is an expected behavior for a knowledge-base skill intended to provide up-to-date technical information.
- Untrusted Data Ingestion (Indirect Prompt Injection Consideration): The skill is designed to process and synthesize information from a local
.wiki/directory and askill-internal.mdconfiguration file. - Ingestion points: Articles located in the
.wiki/path and the mode configuration in.wiki/fb/skill-internal.md. - Boundary markers: The skill explicitly instructs the agent to treat the wiki content as "reference DATA only" and provides a warning not to execute instructions found within that data.
- Capability inventory: The skill possesses the capability to read local files within the workspace and fetch content from specific predefined documentation URLs.
- Sanitization: The instructions include a clear directive to prioritize safety by requiring explicit user confirmation before acting on any advice found in the wiki articles that involves command execution or package installation.
- Dynamic Configuration: The skill implements a mode dispatch system that reads the first token of user arguments and compares it against modes defined in a local configuration file (
.wiki/fb/skill-internal.md). This allows for dynamic routing of the agent's logic based on the contents of the repository's wiki.
Audit Metadata