project
Pass
Audited by Gen Agent Trust Hub on Jul 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill uses the obsidian toolset for legitimate vault management tasks, such as searching, creating, and updating notes. These operations are standard for its stated purpose.
- [SAFE]: All write operations are protected by mandatory user review and confirmation steps, which mitigates the risk of unintended modifications.
- [SAFE]: The skill reads project notes which constitutes an indirect prompt injection surface, but the risk is assessed as safe due to the interactive confirmation workflow. 1. Ingestion points: UPDATE Workflow (Step 2) reads project files from the 1
- Projects/ folder. 2. Boundary markers: Absent. 3. Capability inventory: File search, create, and property updates via obsidian tools. 4. Sanitization: Mandatory user preview and confirmation before writing.
- [SAFE]: There is no evidence of data exfiltration, network communication to untrusted domains, or unauthorized access to sensitive system files.
Audit Metadata