onenote-reference-architecture

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides legitimate technical documentation and architectural patterns for Microsoft Graph API integrations. All external links and code references target official Microsoft services and SDKs.\n- [INDIRECT_PROMPT_INJECTION]: The skill documents an integration that fetches data from an external source (OneNote), which is a common pattern but presents a theoretical surface for indirect prompt injection. This finding is considered safe as it is a functional requirement of the documented integration.\n
  • Ingestion points: OneNote notebook metadata, section titles, and page content retrieved via Graph API calls (referenced in SKILL.md).\n
  • Boundary markers: None present in the service layer code snippets.\n
  • Capability inventory: The skill maps API access to Microsoft Graph for reading and creating notes, and recommends the use of workspace tools like Grep for processing content.\n
  • Sanitization: The skill notes that the Graph API provides basic sanitization by stripping invalid HTML from page content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 02:45 PM
Security Audit — agent-trust-hub — onenote-reference-architecture