extract-graph
Pass
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill defines a workflow with an indirect prompt injection attack surface. It is designed to read and process the contents of arbitrary Obsidian notes to extract entity-relation triples.
- Ingestion points: Reads vault notes provided via the
$ARGUMENTSparameter using theReadtool. - Boundary markers: Absent. The skill documentation does not outline the use of delimiters or specific instructions to the model to ignore potential commands embedded within the source notes.
- Capability inventory: The skill has access to the
BashandWritetools, which are used to modify note frontmatter and manage local directory structures. - Sanitization: While the skill mentions validating the model's JSON output against a schema, it lacks descriptions of sanitization or filtering for the extracted text content.
- [DATA_EXPOSURE]: The skill's implementation example contains a hardcoded absolute file path (
/Users/ethanphan/Documents/my-obsidian-v1). This discloses information regarding the directory structure and username of the development environment. - [COMMAND_EXECUTION]: The skill uses the
Bashtool to perform administrative tasks such as creating storage directories (.graph/nodes,.graph/edges) and is designed to execute a helper script (extract_graph.py) to process data.
Audit Metadata