capture-triage
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from markdown files in an Inbox folder and uses it to drive agent behavior.
- Ingestion points: The skill reads the full content of any
.mdfile found in the/Users/eddale/Documents/COPYobsidian/MAGI/Zettelkasten/Inbox/directory. - Boundary markers: There are no boundary markers or instructions provided to the LLM to ignore potentially malicious instructions embedded within the captures.
- Capability inventory: The skill possesses the ability to edit local files, create new ones, and crucially, spawn a
research-swarmsub-agent. - Sanitization: Raw content from the captures is directly interpolated into the prompt for the sub-agent in Step 7 (
prompt="Research question: [Full capture content]"). A malicious note could contain instructions that hijack the research agent's mission. - [COMMAND_EXECUTION]: The skill instructions explicitly direct the agent to perform shell-based file operations.
- Evidence: Step 1 requires the use of
lsfor file discovery, and Step 9 requiresmvto relocate triaged files. If these are executed via a shell tool without proper escaping, a maliciously crafted filename (e.g., using semicolons or backticks) could lead to command injection on the host system.
Audit Metadata