reading-notes
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and summarize external resources including webpages, YouTube transcripts, PDFs, and user-provided notes. This creates an inherent attack surface where malicious instructions embedded within these external sources (e.g., hidden text in a webpage or a transcript) could attempt to influence the agent's behavior.
- Ingestion points: The
references/intake.mdfile defines comprehensive workflows for fetching and parsing content from various external URLs and file types. - Capability inventory: The skill has the ability to execute local scripts via
subprocess(inscripts/test_skill.py) and generate multiple document formats (Markdown, DOCX, PDF, CSV, XLSX, JSON) as detailed inreferences/output-formats.md. - Boundary markers: Although
SKILL.mdandreferences/synthesis.mdprovide guidance on separating facts from inferences, the skill does not define strict delimiters or "ignore instructions" wrappers when interpolating raw external content into the prompt. - Sanitization: There is no evidence of automated sanitization or filtering of external content before it is processed by the agent.
- [COMMAND_EXECUTION]: The script
scripts/test_skill.pyutilizessubprocess.run()to execute other internal scripts, such asscripts/probe_reading_notes.py, to perform help-text verification and self-tests. While these commands are constructed using static local paths and the current Python executable, they represent a functional capability to launch shell processes. - [DYNAMIC_EXECUTION]: The skill includes a testing framework that dynamically executes local Python scripts to validate the package's integrity. Specifically,
scripts/test_skill.pyinvokes the Python interpreter to runscripts/probe_reading_notes.pywith different arguments to verify its classification logic.
Audit Metadata