knowledge-extractor

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from local project logs and configuration files which could contain instructions intended to influence agent behavior.
  • Ingestion points: In SKILL.md, the behavior sections instruct the agent to load .aidoc/profile.yaml and .aidoc/learnings.md.
  • Boundary markers: There are no explicit instructions provided to the agent to treat the content of these files strictly as data or to ignore embedded natural language instructions.
  • Capability inventory: The skill's capabilities are limited to reading files and drafting text. It explicitly notes that it cannot open pull requests, approve changes, or edit the framework directly.
  • Sanitization: The instructions do not define any sanitization or validation steps for the content found in the external logs.
  • [NO_CODE]: The skill is composed entirely of markdown instructions and metadata, with no accompanying scripts, binaries, or runtime code included.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 09:11 PM
Security Audit — agent-trust-hub — knowledge-extractor