kmp-lessons
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a local Python script
scripts/create_lesson.pyto automate the creation of lesson files within the project'sdocs/lessons/directory. The script uses the standardpathliblibrary to manage file paths and directory creation. - [DATA_EXFILTRATION]: The instructions direct the agent to proactively draft GitHub issues on the
ronjunevaldoz/kmp-agent-skillsrepository when a high-severity bug is identified. This workflow involves preparing project-specific content (code snippets, error messages, and filenames) for external transmission. Although the repository is a vendor-owned resource and the skill mandates an explicit user confirmation gate before submission, this represents a proactive data transfer path. - [INDIRECT_PROMPT_INJECTION]: The skill serves as a data producer for downstream 'harvester' tools that aggregate these lessons to amend other skills. The free-text fields in the generated markdown (e.g., 'What we followed', 'Correct pattern') represent an attack surface where adversarial content could be captured during a project and later processed by other agent skills.
- Ingestion points: Captured project data (bug reports, code fixes) entered into the lesson template.
- Boundary markers: The generated files use standard markdown headers to separate fields but lack specific 'ignore instructions' delimiters for the user-supplied content.
- Capability inventory: The skill performs local file writes via
scripts/create_lesson.pyand initiates external issue drafting via the/report-skill-issuecommand. - Sanitization: Filenames are sanitized via a slugify function to prevent path manipulation, but the content of the lesson body is written without escaping or validation.
Audit Metadata