kb-builder
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
@tiny-fish/clipackage from the NPM registry to enable its core functionality. - [COMMAND_EXECUTION]: The skill uses shell commands to check environment status (
which tinyfish,tinyfish --version), manage authentication (tinyfish auth login), create directories (mkdir), and execute web-browsing tasks (tinyfish agent run). It also employs shell backgrounding and thewaitcommand to manage parallel execution of discovery and reading tasks. - [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and process untrusted data from the live web, creating a potential vector for malicious content to influence agent behavior.
- Ingestion points: External URLs are accessed via
tinyfish agent runduring both the discovery pass and the reading pass inSKILL.md. - Boundary markers: The skill uses specific prompts requesting JSON output to structure the extraction, but it does not implement explicit boundary markers or delimiters to isolate untrusted web content from the agent's instructions.
- Capability inventory: The skill has the capability to execute shell commands (via the
tinyfishCLI), create directories, and write multiple markdown and JSON files to the local file system. - Sanitization: There is no evidence of explicit content sanitization, filtering, or validation of the data extracted from web pages before it is processed by the agent to build the knowledge base.
Audit Metadata