obsidian-clipper-template-creator

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions require the agent to fetch and analyze external web pages provided by the user to extract selectors and schema data. This creates a surface for indirect prompt injection where malicious instructions embedded in a target website could attempt to override the agent's instructions or influence the generated template output.
  • Ingestion points: Page content retrieved via the WebFetch tool as described in references/analysis-workflow.md.
  • Boundary markers: The skill does not define explicit delimiters or instructions to ignore embedded commands within the fetched HTML/JSON data.
  • Capability inventory: The skill possesses the capability to fetch external network resources (WebFetch) and read local configuration files within the Templates/Bases/ directory.
  • Sanitization: No specific sanitization or validation logic is defined for the external content before it is processed by the agent.
  • [COMMAND_EXECUTION]: The skill uses the WebFetch tool to dynamically retrieve content from URLs. Although this is the primary purpose of the skill, the execution is driven by external, potentially untrusted user input.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:32 PM
Security Audit — agent-trust-hub — obsidian-clipper-template-creator