skills/ethan-rio/skills/recall/Gen Agent Trust Hub

recall

Warn

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The Workflow (prototype — graph + grep) section contains a bash script that interpolates user-controlled input ($ARGUMENTS) into a subshell: $(echo "$Q" | tr ' ' '|'). An attacker can supply shell command substitution patterns (e.g., $(command)) within their question to execute arbitrary code on the host system.
  • [PROMPT_INJECTION]: The skill exhibits an Indirect Prompt Injection surface. It retrieves content from the user's Obsidian vault notes and directs the agent to "Read each hit" and "compose an answer grounded in those notes." If a note contains malicious instructions, the agent may follow them, potentially leveraging its Read, Bash, and Write capabilities to perform unauthorized actions.
  • Ingestion points: Files retrieved via grep from the VAULT path in SKILL.md.
  • Boundary markers: Absent. There are no instructions to the agent to ignore or delimit instructions found within the retrieved notes.
  • Capability inventory: The skill has access to Read, Bash, and Write tools as defined in the YAML frontmatter.
  • Sanitization: Absent. The retrieved content is passed directly to the agent for processing without escaping or validation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 18, 2026, 01:51 PM
Security Audit — agent-trust-hub — recall