onenote-common-errors

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is a diagnostic utility for API error classification and does not contain executable code, obfuscation, or persistence mechanisms. It promotes safe credential management by explicitly forbidding the inclusion of bearer tokens or raw secrets in artifacts.\n- [EXTERNAL_DOWNLOADS]: The skill references official Microsoft Graph documentation and API references. These links point to well-known, trusted domains for technical reference.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes external API response data, creating a potential ingestion surface. However, the risk is mitigated by explicit instructions to redact secrets and notebook content.\n
  • Ingestion points: Redacted response envelopes and documentation files (SKILL.md, references/official-docs.md).\n
  • Boundary markers: Instructions mandate the use of redacted envelopes and synthetic fixtures.\n
  • Capability inventory: File system access via Read, Glob, Grep, Write, and Edit tools.\n
  • Sanitization: Mandatory removal of secrets and real notebook content before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 02:44 PM
Security Audit — agent-trust-hub — onenote-common-errors