ingest-quick-note

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data that is later stored and potentially processed by other agent skills.
  • Ingestion points: Untrusted data enters the skill via the $ARGUMENTS variable in SKILL.md, which contains the raw text body provided by the user.
  • Boundary markers: There are no boundary markers or delimiters used when saving the content to the vault to prevent downstream agents from interpreting the note body as instructions.
  • Capability inventory: The skill utilizes the Bash Write tool to execute new_note.sh, which performs file system write operations within the $OBSIDIAN_VAULT directory.
  • Sanitization: While the code sanitizes the SLUG used for the filename, the --title and the stdin BODY are passed to the writing script without escaping or filtering malicious instructions.
  • [COMMAND_EXECUTION]: The skill executes a local shell script located at a relative path (../obsidian-vault/scripts/new_note.sh). This script is used to enforce the vault's schema and structure during note creation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 04:18 AM
Security Audit — agent-trust-hub — ingest-quick-note