xhs-analyze
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (content extracted from Little Red Book) saved within a local directory.
- Ingestion points: The skill reads all
.mdfiles located in the~/Documents/Obsidian Vault/xhsdirectory to perform analysis and summaries. - Boundary markers: There are no explicit instructions to use delimiters or ignore potentially malicious instructions embedded within the saved bookmarks.
- Capability inventory: The skill is granted access to powerful tools including
Bash,Read,Glob, andGrep. - Sanitization: No sanitization or filtering is applied to the content before it is passed to the AI for summarization, creating a surface where malicious text in a bookmark could influence the agent's behavior.
Audit Metadata