obsidian-clipper-template-creator
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions require the agent to fetch and analyze external web pages provided by the user to extract selectors and schema data. This creates a surface for indirect prompt injection where malicious instructions embedded in a target website could attempt to override the agent's instructions or influence the generated template output.
- Ingestion points: Page content retrieved via the
WebFetchtool as described inreferences/analysis-workflow.md. - Boundary markers: The skill does not define explicit delimiters or instructions to ignore embedded commands within the fetched HTML/JSON data.
- Capability inventory: The skill possesses the capability to fetch external network resources (
WebFetch) and read local configuration files within theTemplates/Bases/directory. - Sanitization: No specific sanitization or validation logic is defined for the external content before it is processed by the agent.
- [COMMAND_EXECUTION]: The skill uses the
WebFetchtool to dynamically retrieve content from URLs. Although this is the primary purpose of the skill, the execution is driven by external, potentially untrusted user input.
Audit Metadata