ingest-quick-note
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data that is later stored and potentially processed by other agent skills.
- Ingestion points: Untrusted data enters the skill via the
$ARGUMENTSvariable inSKILL.md, which contains the raw text body provided by the user. - Boundary markers: There are no boundary markers or delimiters used when saving the content to the vault to prevent downstream agents from interpreting the note body as instructions.
- Capability inventory: The skill utilizes the
Bash Writetool to executenew_note.sh, which performs file system write operations within the$OBSIDIAN_VAULTdirectory. - Sanitization: While the code sanitizes the
SLUGused for the filename, the--titleand the stdinBODYare passed to the writing script without escaping or filtering malicious instructions. - [COMMAND_EXECUTION]: The skill executes a local shell script located at a relative path (
../obsidian-vault/scripts/new_note.sh). This script is used to enforce the vault's schema and structure during note creation.
Audit Metadata