getnote-dsh

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes external content from note searches and specific note requests, which could contain malicious instructions designed to influence the agent.
  • Ingestion points: Note data ingested through getnote_search and getnote_get_note tools.
  • Boundary markers: The instructions do not define delimiters or markers to separate untrusted note data from the agent's instructions.
  • Capability inventory: The skill restricts the agent to specific getnote tools and prohibits arbitrary shell command construction, reducing the impact of potential injections.
  • Sanitization: There is no evidence of content sanitization or validation for the retrieved data.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to execute a command that fetches and runs a package from the NPM registry.
  • Evidence: The authentication section suggests running npx @getnote/cli@latest auth login in the terminal.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 03:00 PM