skills/ethan-rio/skills/daily-review/Gen Agent Trust Hub

daily-review

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses local shell commands such as find, grep, awk, and stat to analyze markdown files within a user-defined Obsidian vault directory. All operations are restricted to the local file system and are consistent with the skill's stated purpose of housekeeping and metadata analysis.
  • [DATA_EXFILTRATION]: No unauthorized network operations or data transfers were detected. The skill generates a local digest file in /tmp/hermes-digest.md and outputs the result to the standard output. References to external notification services like Telegram are provided as examples for platform-level cron configuration rather than being implemented as executable commands within the skill's script.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes content from the vault (markdown files) which may include untrusted data if the vault contains web clippings. This represents an ingestion surface for indirect prompt injection; however, the script's logic is primarily focused on metadata extraction (tags, link existence) rather than interpreting or executing instructions found within the vault content, posing a minimal security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 01:51 PM
Security Audit — agent-trust-hub — daily-review