receive
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection because it ingests and processes content from external files located in the
~/Obsidian/Handoffs/directory and follows associated wikilinks. - Ingestion points: External Markdown files in
~/Obsidian/Handoffs/and linked pages in the Library or Profile. - Boundary markers: The instructions lack explicit delimiters or warnings to treat ingested file content as untrusted data.
- Capability inventory: The skill performs file system operations including listing, reading, and moving (archiving) files within the user's home directory.
- Sanitization: There is no mention of sanitizing or validating the content read from external files before it is incorporated into the agent's context.
Audit Metadata