obsidian
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes user-supplied paths and persists them to a configuration file (
~/.atomic-agent/.env). While this is a functional setup feature, an attacker could provide a malicious path or a path containing environment variable overrides to influence the agent's future behavior. - Ingestion points: User-supplied paths provided during the "Vault path does not exist" or "Resolved path is not a real vault" playbooks (SKILL.md).
- Boundary markers: Absent. The skill instructions tell the agent to take the
<user-supplied-path>and append it directly to the.envfile. - Capability inventory:
os.fs.read,os.fs.glob,os.fs.grep,os.fs.write,os.fs.list,os.shell.run(SKILL.md). - Sanitization: Absent. There is no validation to ensure the path does not contain shell escape characters or newline-injected environment variables before writing to the
.envfile.
Audit Metadata