life-capture
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security risks were detected. The skill adheres to role-based constraints defined in ROLE.md which enforce human-in-the-loop validation for vault modifications and strictly prohibit autonomous product implementation.
- [INDIRECT_PROMPT_INJECTION]: The skill displays an ingestion surface where raw user text is written to files (SKILL.md § Recipe). Ingestion point: User-provided text for 'Body'; Boundary markers: None; Capability inventory: File write to configuration-defined 'layout.inbox_dir'; Sanitization: None. This vulnerability surface is the intended primary delivery mechanism of the 'capture' skill and is considered safe within its restricted execution scope.
Audit Metadata