video-note
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes markdown content from an external source (Obsidian vault) which can contain untrusted data. Malicious instructions embedded within these notes could potentially manipulate the agent's behavior during the rewriting and publishing process.
- Ingestion points: Reads
.mdfiles from/Users/joel/Vault/Resources/videos/as specified inSKILL.mdandreferences/content-system.md. - Boundary markers: None identified; the instructions do not specify delimiters or warnings to ignore instructions embedded in the source notes.
- Capability inventory: The skill performs file system read and write operations to transform vault notes into site content.
- Sanitization: No content sanitization or validation is mentioned prior to processing the note text.
- [DATA_EXFILTRATION]: The skill is designed to access sensitive file paths within the user's home directory (
/Users/joel/Vault/). While consistent with the stated purpose for the author 'joelhooks', this access allows for the exposure of private notes and metadata, such as NAS paths listed in the source frontmatter. - [COMMAND_EXECUTION]: The documentation in
references/content-system.mdincludes shell commands (ls /Users/joel/Vault/Resources/videos/*.md) that the agent is expected to execute to list and interact with the local file system.
Audit Metadata