capture-receipt
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by processing data from untrusted sources to determine its actions.
- Ingestion points: Information is harvested from the current session, today's note, code snippets, and user-provided text (SKILL.md, Section 2).
- Boundary markers: There are no technical delimiters (such as XML tags) mentioned for the data ingestion process.
- Capability inventory: The skill has permissions to write to local markdown files and initiate handoffs to external skills for tweeting or blogging (SKILL.md, Section 4 & 5).
- Sanitization: Security is addressed through a safety gate review process and a requirement for explicit user approval before writing content or triggering external handoffs (SKILL.md, Section 3 & 5).
Audit Metadata