knowledge-capture
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION] (LOW): Indirect Prompt Injection surface detected in documentation workflows.
- Ingestion points: The skill ingests untrusted data from the
docs/directory using theReadandGreptools during the deduplication and staleness detection phases inSKILL.md. - Boundary markers: Absent. There are no instructions to the agent to treat the contents of the documentation files as data rather than instructions.
- Capability inventory: The skill possesses
WriteandEditcapabilities, which could be misused if a processed document successfully injects instructions into the agent's context. - Sanitization: Absent. No sanitization or validation is applied to the content of the markdown files before they are read or edited by the agent.
Audit Metadata