ant-design-knowledge-base
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [Indirect Prompt Injection] (LOW): The skill ingests data from local knowledge base files, creating a potential surface for indirect prompt injection.
- Ingestion points:
knowledge-base/llms.txtandknowledge-base/llms-full.txt(SKILL.md). - Boundary markers: Absent. No explicit delimiters or instructions are provided to help the agent distinguish between documentation and potential embedded commands.
- Capability inventory: The skill is authorized to use
Read,Grep, andGlobtools to access the filesystem. - Sanitization: Absent. Content from the knowledge base is read and processed without any sanitization or validation steps.
Audit Metadata