quick-wins

Pass

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute shell commands including ls, wc, and jq, as well as specialized commands for the obsidian CLI to query and update local vault data. These operations are scoped to the user's local path at /Users/bonny/Documents/nvALT/.- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface (Category 8) by reading and triaging instructions found in the bodies of local issue files.\n
  • Ingestion points: Issue content is read from markdown files located in the local vault (SKILL.md).\n
  • Boundary markers: Absent. The skill does not employ delimiters or system instructions to ignore potential commands embedded within the issue text.\n
  • Capability inventory: The skill can execute arbitrary shell commands via Bash and modify local files using the obsidian CLI tool.\n
  • Sanitization: Absent. No validation or filtering is applied to the issue body content before the agent triages or implements the suggested fixes.
Audit Metadata
Risk Level
SAFE
Analyzed
May 17, 2026, 05:48 PM
Security Audit — agent-trust-hub — quick-wins