skills/kriscard/skills/project/Gen Agent Trust Hub

project

Pass

Audited by Gen Agent Trust Hub on Jul 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill uses the obsidian toolset for legitimate vault management tasks, such as searching, creating, and updating notes. These operations are standard for its stated purpose.
  • [SAFE]: All write operations are protected by mandatory user review and confirmation steps, which mitigates the risk of unintended modifications.
  • [SAFE]: The skill reads project notes which constitutes an indirect prompt injection surface, but the risk is assessed as safe due to the interactive confirmation workflow. 1. Ingestion points: UPDATE Workflow (Step 2) reads project files from the 1
  • Projects/ folder. 2. Boundary markers: Absent. 3. Capability inventory: File search, create, and property updates via obsidian tools. 4. Sanitization: Mandatory user preview and confirmation before writing.
  • [SAFE]: There is no evidence of data exfiltration, network communication to untrusted domains, or unauthorized access to sensitive system files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 5, 2026, 07:44 PM
Security Audit — agent-trust-hub — project