kmp-skill-harvester
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted Markdown files and GitHub issues from external sources to propose and apply changes to its own codebase.
- Ingestion points: The
scripts/harvest_lessons.pyscript reads files fromdocs/lessons/*.mdin directories specified by the user, and the skill also fetches external GitHub issues via theghCLI. - Boundary markers: The instructions tell the agent to "Show the user a summary before touching any skill file" and "Only apply changes after explicit confirmation", providing a human-in-the-loop checkpoint.
- Capability inventory: The agent has the capability to write to the file system (modifying
SKILL.mdand reference files) and potentially commit changes viagit. - Sanitization: There is no evidence of sanitization or filtering of the content within the external files or issues to prevent embedded instructions from influencing the agent's behavior during the "harvesting" process.
- [COMMAND_EXECUTION]: Executes a bundled Python script
scripts/harvest_lessons.pyto parse lesson files and the GitHub CLI (gh) to fetch lesson-related issues from the repositoryronjunevaldoz/kmp-agent-skills.
Audit Metadata