obsidian-workout-export

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The README.md file contains local file system paths (C:/Users/mick0/...) which reveal the directory structure of the author's development environment. This is an informational finding and does not pose a security risk to the user or the agent's execution environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from the current and prior chat history. While there are no explicit boundary markers or instructions to ignore potential commands embedded in workout data, the skill uses highly prescriptive instructions to extract specific data points into Markdown tables and YAML frontmatter, which inherently limits the effectiveness of injected instructions.
  • [REMOTE_CODE_EXECUTION]: No remote code execution or package installation patterns were detected. The .skill file is a standard ZIP archive containing the plain-text source files provided in the skill folder.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 01:06 AM
Security Audit — agent-trust-hub — obsidian-workout-export