vault-lint

Pass

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes content from the notes/ and projects/ directories, creating a surface for potential indirect prompt injection.
  • Ingestion points: notes/ and projects/ directories specified in the Scope section.
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore potentially malicious instructions inside the files.
  • Capability inventory: The skill reads file contents and has the capability to write link corrections in apply mode.
  • Sanitization: No sanitization or validation of the ingested text content is described.
  • [NO_CODE]: The skill is composed entirely of natural language instructions and configuration metadata; it does not contain or reference external scripts, binaries, or package dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 18, 2026, 12:24 PM
Security Audit — agent-trust-hub — vault-lint