capture-receipt

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by processing data from untrusted sources to determine its actions.
  • Ingestion points: Information is harvested from the current session, today's note, code snippets, and user-provided text (SKILL.md, Section 2).
  • Boundary markers: There are no technical delimiters (such as XML tags) mentioned for the data ingestion process.
  • Capability inventory: The skill has permissions to write to local markdown files and initiate handoffs to external skills for tweeting or blogging (SKILL.md, Section 4 & 5).
  • Sanitization: Security is addressed through a safety gate review process and a requirement for explicit user approval before writing content or triggering external handoffs (SKILL.md, Section 3 & 5).
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 03:21 PM
Security Audit — agent-trust-hub — capture-receipt