kg-extract
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides an alternative command using npx to download a package from the npm registry at runtime.\n
- Evidence: The CLI alternative section specifies npx @claude-flow/cli@latest.\n- [REMOTE_CODE_EXECUTION]: The skill suggests the execution of an external CLI tool downloaded at runtime without version pinning.\n
- Evidence: The npx command execution of @claude-flow/cli@latest.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external source code and documentation files which can contain malicious instructions.\n
- Ingestion points: The Read and Glob tools are used to ingest file contents from a provided path (SKILL.md).\n
- Boundary markers: The skill does not define specific delimiters or warnings to ignore instructions embedded within the scanned files.\n
- Capability inventory: The skill uses Bash and writes to AgentDB via hierarchical-store and causal-edge tools (SKILL.md).\n
- Sanitization: There is no evidence of sanitization or validation of the content extracted from source files before storage.
Audit Metadata