knowledge-capture

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION] (LOW): Indirect Prompt Injection surface detected in documentation workflows.
  • Ingestion points: The skill ingests untrusted data from the docs/ directory using the Read and Grep tools during the deduplication and staleness detection phases in SKILL.md.
  • Boundary markers: Absent. There are no instructions to the agent to treat the contents of the documentation files as data rather than instructions.
  • Capability inventory: The skill possesses Write and Edit capabilities, which could be misused if a processed document successfully injects instructions into the agent's context.
  • Sanitization: Absent. No sanitization or validation is applied to the content of the markdown files before they are read or edited by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:12 PM