second-brain

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/scaffold.py script uses subprocess.run to execute a local bash script (validate-artifacts.sh) during its self-test procedure to verify the integrity of the vault structure.\n- [PROMPT_INJECTION]: The skill incorporates an autonomous ingestion loop and a multi-stage compilation pipeline that processes data from external connectors such as Gmail and Notion. This ingestion process creates a surface for indirect prompt injection where malicious instructions embedded in raw source documents could potentially influence agent logic during parsing, classification, or extraction.\n
  • Ingestion points: Raw external content is ingested into the raw/ directory from third-party connectors.\n
  • Boundary markers: The system uses structured checkpoints via state.json and INGESTION-LOG.md to track state and enforce hard gates between ingestion phases.\n
  • Capability inventory: The skill has the capability to write, update, and organize Markdown notes across various domain folders in the vault based on model-extracted claims.\n
  • Sanitization: The pipeline includes a 'critic' pass designed to audit generated notes against their sources and uses scan-secrets.py to identify and redact sensitive tokens.\n- [DATA_EXFILTRATION]: The skill manages sensitive personal and professional data within an Obsidian vault. To mitigate risks, it includes a scripts/scan-secrets.py utility that scans for a wide range of credential shapes (e.g., AWS keys, GitHub tokens, private keys) and masks them before the vault is finalized, acknowledging the risk of sensitive data exposure during bulk ingestion.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 07:15 PM
Security Audit — agent-trust-hub — second-brain