recall
Warn
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
Workflow (prototype — graph + grep)section contains a bash script that interpolates user-controlled input ($ARGUMENTS) into a subshell:$(echo "$Q" | tr ' ' '|'). An attacker can supply shell command substitution patterns (e.g.,$(command)) within their question to execute arbitrary code on the host system. - [PROMPT_INJECTION]: The skill exhibits an Indirect Prompt Injection surface. It retrieves content from the user's Obsidian vault notes and directs the agent to "Read each hit" and "compose an answer grounded in those notes." If a note contains malicious instructions, the agent may follow them, potentially leveraging its
Read,Bash, andWritecapabilities to perform unauthorized actions. - Ingestion points: Files retrieved via
grepfrom theVAULTpath inSKILL.md. - Boundary markers: Absent. There are no instructions to the agent to ignore or delimit instructions found within the retrieved notes.
- Capability inventory: The skill has access to
Read,Bash, andWritetools as defined in the YAML frontmatter. - Sanitization: Absent. The retrieved content is passed directly to the agent for processing without escaping or validation.
Audit Metadata