lode-monthly-review

Pass

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes internal Python scripts (scripts/split_daily_note.py and scripts/prepare_monthly_data.py) to perform its primary functions of splitting files and extracting data. These scripts are bundled with the skill and use standard Python libraries for file processing without any malicious behavior detected.- [DATA_EXFILTRATION]: The skill accesses local configuration files (e.g., ~/.lode/config.yaml) and environment variables to determine directory paths for its operations. There are no network operations, and all processed data is stored within the user's local filesystem.- [PROMPT_INJECTION]: The skill processes user-generated daily notes to create summaries. It includes specific instructional guardrails such as 'evidence_mode=strict', 'fact-based only', and 'prohibit fictionalizing conclusions' to ensure the AI agent remains faithful to the source data and mitigates risks associated with potential indirect prompt injections within the processed notes.
Audit Metadata
Risk Level
SAFE
Analyzed
May 12, 2026, 09:55 AM
Security Audit — agent-trust-hub — lode-monthly-review