inbox-processor
Pass
Audited by Gen Agent Trust Hub on May 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill instructions create a vulnerability surface for indirect prompt injection by processing untrusted data.
- Ingestion points: The skill reads all content from files located in the '00_Inbox/' directory.
- Boundary markers: There are no instructions to use delimiters or specific ignore-rules for the content of the notes being analyzed.
- Capability inventory: The skill generates an action plan for moving and deleting files, which could be exploited if an ingested note contains malicious instructions.
- Sanitization: There is no evidence of sanitization, validation, or escaping of the content read from the inbox files.
Audit Metadata