obsidian

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes user-supplied paths and persists them to a configuration file (~/.atomic-agent/.env). While this is a functional setup feature, an attacker could provide a malicious path or a path containing environment variable overrides to influence the agent's future behavior.
  • Ingestion points: User-supplied paths provided during the "Vault path does not exist" or "Resolved path is not a real vault" playbooks (SKILL.md).
  • Boundary markers: Absent. The skill instructions tell the agent to take the <user-supplied-path> and append it directly to the .env file.
  • Capability inventory: os.fs.read, os.fs.glob, os.fs.grep, os.fs.write, os.fs.list, os.shell.run (SKILL.md).
  • Sanitization: Absent. There is no validation to ensure the path does not contain shell escape characters or newline-injected environment variables before writing to the .env file.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 05:52 PM
Security Audit — agent-trust-hub — obsidian