journal
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill ingests user-authored journal entries from the
00-Inbox/Journals/directory to summarize patterns and inform daily planning. It lacks explicit boundary markers or sanitization for this external content, creating a surface for indirect prompt injection (Category 8) where text within a journal could attempt to influence the agent's logic during subsequent processing steps.\n- [DATA_EXFILTRATION]: The skill performs silent analytics via thetrack_eventfunction. This is documented as an opt-in feature that only transmits metadata regarding the type of journal created rather than sensitive user content.
Audit Metadata