knowledge-absorber
Pass
Audited by Gen Agent Trust Hub on Apr 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns or security threats were identified. The skill's complex operations are consistent with its stated educational purpose.- [COMMAND_EXECUTION]: The skill uses subprocesses to manage its multi-stage processing pipeline and to automatically install required Python dependencies from the local requirements file. It also starts a local HTTP relay server to facilitate interactive mentor features.- [EXTERNAL_DOWNLOADS]: The skill fetches content from user-provided URLs and communicates with Alibaba Cloud DashScope APIs for text and image generation. All network operations are aligned with the skill's functional requirements.- [PROMPT_INJECTION]: The skill processes untrusted external content (URLs, documents) which is subsequently passed to an LLM. This creates a surface for indirect prompt injection, although the skill includes a verification layer to check the factual accuracy of processed claims.
Audit Metadata