vault-process

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests data from the raw/sources/ directory. 1. Ingestion points: files located in raw/sources/. 2. Boundary markers: none specified to delimit processed data. 3. Capability inventory: file system modifications in notes/ and projects/, file movement for archival, and execution of vault-qmd. 4. Sanitization: none mentioned.
  • [COMMAND_EXECUTION]: The skill executes the local command vault-qmd --mode apply-safe to refresh indices after processing durable pages.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 12:34 AM
Security Audit — agent-trust-hub — vault-process