onenote-core-workflow-a

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists entirely of instructional markdown and documentation for a OneNote inventory workflow. It does not include any executable code, scripts, or suspicious command patterns.
  • [EXTERNAL_DOWNLOADS]: The skill references official Microsoft Graph documentation for API contracts. These references target a well-known service domain (learn.microsoft.com) and are used for providing technical context.
  • [INDIRECT_PROMPT_INJECTION]: The workflow involves processing data from the OneNote API. The skill mitigates risks associated with processing untrusted external data by requiring explicit approval for new notebook roots and prioritizing stable server-generated IDs over mutable titles.
  • Ingestion points: OneNote API hierarchy and metadata responses (SKILL.md).
  • Boundary markers: Explicit approval boundaries for content owners and environment-specific evidence recording (SKILL.md).
  • Capability inventory: Tools are restricted to local file operations (Read, Glob, Grep, Write, Edit) for evidence and configuration management.
  • Sanitization: Focuses on identity resolution and following opaque next links unchanged.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 02:44 PM
Security Audit — agent-trust-hub — onenote-core-workflow-a