capture-idea

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted transcription output from audio files and uses it to generate project documentation and specifications. This creates an attack surface where instructions hidden in the audio could potentially influence the agent's file creation or repository operations.
  • Ingestion points: Transcription output received from the Gemini MCP tool (SKILL.md).
  • Boundary markers: None provided in the instructions to separate the transcript content from the agent's operational instructions.
  • Capability inventory: File system write access (creating CLAUDE.md, README.md, and spec files) and network operations (pushing to GitHub).
  • Sanitization: There are no explicit instructions to sanitize or validate the content of the transcripts before writing them to the repository or using them to derive specifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 09:31 PM
Security Audit — agent-trust-hub — capture-idea