vestige-record-note

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it processes untrusted user input and interpolates it into executable shell commands.
  • Ingestion points: The body positional argument for the vestige note add command is derived directly from user-supplied text (e.g., "jot this down") as described in SKILL.md.
  • Boundary markers: The skill instructions use double quotes ("<the fact>") as delimiters in the command template, but do not provide instructions for the agent to escape nested quotes or shell metacharacters (e.g., ;, &&, |).
  • Capability inventory: The skill performs shell command execution using the vestige CLI tool (SKILL.md).
  • Sanitization: There is an absence of explicit sanitization or validation guidelines to ensure that user input does not break out of the command string.
  • [COMMAND_EXECUTION]: The skill is designed to execute local shell commands (vestige note add, vestige recall) to manage project memories. While this is the intended primary purpose of the skill, the lack of input validation for the interpolated strings is a noteworthy security consideration.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 03:20 PM
Security Audit — agent-trust-hub — vestige-record-note