personal-strategic-signal-intelligence
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a set of analytical instructions and does not include any executable code, shell scripts, or external dependencies.
- [DATA_EXFILTRATION]: While the skill processes private user data (bookmarks, highlights, notes), it explicitly instructs the agent to use read-only, least-privilege connectors and to keep credentials in protected secret storage. It emphasizes data minimization and requires explicit user approval before any external publishing or modification.
- [PROMPT_INJECTION]: The skill includes a 'Source Contract' that normalizes external data into structured YAML formats before processing. This acts as a boundary to mitigate potential indirect prompt injection from untrusted source material like bookmarks or web highlights.
Audit Metadata