notes-generator

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill architecture involves reading from external sources and writing to the local file system, which creates a surface for indirect prompt injection if source material contains malicious instructions.\n
  • Ingestion points: Data is ingested through the Read tool for local reference files and the WebFetch tool for external educational content as part of the research phase in Phase 1 of SKILL.md.\n
  • Boundary markers: The instructions do not specify the use of delimiters or clear separation between ingested content and the agent's instructions, nor do they include warnings to ignore embedded directives in the source material.\n
  • Capability inventory: The skill uses a combination of data-gathering tools (Read, WebSearch, WebFetch), interaction tools (AskUserQuestion), and a file-writing tool (Write) to produce the final output.\n
  • Sanitization: There are no instructions for sanitizing, filtering, or validating external content before it is used to generate the final notes or written to the disk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 01:31 PM
Security Audit — agent-trust-hub — notes-generator