kmp-skill-harvester

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted Markdown files and GitHub issues from external sources to propose and apply changes to its own codebase.
  • Ingestion points: The scripts/harvest_lessons.py script reads files from docs/lessons/*.md in directories specified by the user, and the skill also fetches external GitHub issues via the gh CLI.
  • Boundary markers: The instructions tell the agent to "Show the user a summary before touching any skill file" and "Only apply changes after explicit confirmation", providing a human-in-the-loop checkpoint.
  • Capability inventory: The agent has the capability to write to the file system (modifying SKILL.md and reference files) and potentially commit changes via git.
  • Sanitization: There is no evidence of sanitization or filtering of the content within the external files or issues to prevent embedded instructions from influencing the agent's behavior during the "harvesting" process.
  • [COMMAND_EXECUTION]: Executes a bundled Python script scripts/harvest_lessons.py to parse lesson files and the GitHub CLI (gh) to fetch lesson-related issues from the repository ronjunevaldoz/kmp-agent-skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 05:50 AM
Security Audit — agent-trust-hub — kmp-skill-harvester