knowledge-extractor
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from local project logs and configuration files which could contain instructions intended to influence agent behavior.
- Ingestion points: In
SKILL.md, the behavior sections instruct the agent to load.aidoc/profile.yamland.aidoc/learnings.md. - Boundary markers: There are no explicit instructions provided to the agent to treat the content of these files strictly as data or to ignore embedded natural language instructions.
- Capability inventory: The skill's capabilities are limited to reading files and drafting text. It explicitly notes that it cannot open pull requests, approve changes, or edit the framework directly.
- Sanitization: The instructions do not define any sanitization or validation steps for the content found in the external logs.
- [NO_CODE]: The skill is composed entirely of markdown instructions and metadata, with no accompanying scripts, binaries, or runtime code included.
Audit Metadata