yuque-personal-knowledge-connect

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes document content to build knowledge maps and cross-references, creating a surface for indirect prompt injection. 1. Ingestion points: Document content retrieved via the yuque_get_doc tool as described in SKILL.md. 2. Boundary markers: Absent; there are no specific instructions for the agent to use delimiters or to treat the retrieved content as untrusted data. 3. Capability inventory: The skill has search, read, and write capabilities within the Yuque platform using tools like yuque_search, yuque_get_doc, yuque_update_doc, and yuque_create_doc (SKILL.md). 4. Sanitization: No explicit sanitization or filtering of external content is defined; however, the skill mitigates risk by instructing the agent to ask the user for permission before updating any document.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:19 PM
Security Audit — agent-trust-hub — yuque-personal-knowledge-connect