soia-pkm-bootstrap-vault-base

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [SAFE]: The skill is designed for local knowledge base initialization using static templates and a Python management script.
  • [COMMAND_EXECUTION]: The init_vault.py script executes local file system commands to create directories and write files. It includes a security-hardened path resolution mechanism that prevents writing outside the intended target directory, mitigating path traversal risks.
  • [EXTERNAL_DOWNLOADS]: The skill manifest declares optional external dependencies for specific integrations. These include an integration from a well-known technology provider and a third-party repository, both managed via the platform's standard skill installation tool.
  • [DATA_EXFILTRATION]: The generated vault configuration includes comprehensive rules for AI agents that explicitly forbid the inclusion of credentials, secrets, or private session data in the knowledge base.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 08:04 AM
Security Audit — agent-trust-hub — soia-pkm-bootstrap-vault-base