getnote-dsh
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes external content from note searches and specific note requests, which could contain malicious instructions designed to influence the agent.
- Ingestion points: Note data ingested through getnote_search and getnote_get_note tools.
- Boundary markers: The instructions do not define delimiters or markers to separate untrusted note data from the agent's instructions.
- Capability inventory: The skill restricts the agent to specific getnote tools and prohibits arbitrary shell command construction, reducing the impact of potential injections.
- Sanitization: There is no evidence of content sanitization or validation for the retrieved data.
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to execute a command that fetches and runs a package from the NPM registry.
- Evidence: The authentication section suggests running npx @getnote/cli@latest auth login in the terminal.
Audit Metadata