curate
Pass
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface because it reads and summarizes content from arbitrary Markdown files in the 'Inbox' folder.
- Ingestion points: The agent reads files from
$VAULT/Inbox/*.mdas specified in the workflow. - Boundary markers: There are no explicit delimiters or instructions (e.g., 'ignore embedded instructions') used when the agent summarizes the note content for the user.
- Capability inventory: The skill utilizes
Bash,Write, andEdittools, allowing for file system modification and shell command execution which could be targeted by a successful injection. - Sanitization: No sanitization or validation of the note body or frontmatter content is performed before processing.
- [COMMAND_EXECUTION]: The skill executes shell commands and Python scripts to perform file operations like moving, merging, and deleting notes.
- Evidence: The 'Promote', 'Merge', and 'Discard' sections contain Bash scripts using
ls,rm,awk, andpython3heredocs to manipulate vault files. - Risk: There is a potential for command injection if the
$TITLEprovided by the user viaAskUserQuestionor the filenames in the Inbox contain shell metacharacters that are not correctly escaped by the agent logic before being passed to the shell.
Audit Metadata