soia-pkm-interpret

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it reads and processes arbitrary article content from a user's filesystem. \n
  • Ingestion points: Article and paper files located within the <vault-articles-dir>/ directory as specified in SKILL.md. \n
  • Boundary markers: Absent; the agent does not use delimiters or instructions to ignore potential commands embedded in the documents it interprets. \n
  • Capability inventory: Read access to articles and write access to create interpretation files (<原文件名>-AI解读.md). \n
  • Sanitization: Absent; the skill does not perform validation or filtering on the article text before processing. \n- [DATA_EXFILTRATION]: The skill requires access to the user's local articles for reading and interpretation. While no network exfiltration patterns were detected in the instructions, the broad read access to user documents represents a potential data exposure surface. \n- [EXTERNAL_DOWNLOADS]: The skill's installation process utilizes npx to fetch content from the soia-team/soia-open-skills repository. This is a standard platform installation pattern and originates from the identified author's namespace.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 03:44 PM
Security Audit — agent-trust-hub — soia-pkm-interpret