erning-obsidian-capture

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes system commands including git (for repository verification and optional initialization) and date (to generate timestamps for directory naming). These operations are targeted at the user's local filesystem and the specific vendor repository github.com/erning/Obsidian-Notes.
  • [INDIRECT_PROMPT_INJECTION]: The skill is instructed to read AGENTS.md files and "relevant nearby notes" within the vault to learn local conventions. This creates a surface where malicious instructions embedded in those existing files could influence the agent's behavior.
  • Ingestion points: AGENTS.md files in the vault and ancestor directories, as well as existing notes near the capture destination.
  • Boundary markers: The instructions do not specify the use of delimiters or safety prompts to prevent the agent from following instructions found within the vault data.
  • Capability inventory: The skill enables file writing and Git operations on the local filesystem.
  • Sanitization: No specific sanitization or validation logic is defined for the content retrieved from the vault.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 04:15 PM
Security Audit — agent-trust-hub — erning-obsidian-capture