knowledge-distribution

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided information such as skill names and descriptions to generate SKILL.md files and directory structures. While this presents a potential ingestion point for prompt injection, the risk is minimized by the skill's specific focus on structural generation rather than direct execution of the metadata content.
  • Ingestion points: User-provided skill name and description.
  • Boundary markers: None explicitly defined in the provided documentation.
  • Capability inventory: File writing (directory creation, SKILL.md generation), packaging (zip creation), and Slack messaging tools.
  • Sanitization: Not explicitly detailed, but behavior is restricted to templated file creation and notification dispatch.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 04:59 PM
Security Audit — agent-trust-hub — knowledge-distribution