capture-triage

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from markdown files in an Inbox folder and uses it to drive agent behavior.
  • Ingestion points: The skill reads the full content of any .md file found in the /Users/eddale/Documents/COPYobsidian/MAGI/Zettelkasten/Inbox/ directory.
  • Boundary markers: There are no boundary markers or instructions provided to the LLM to ignore potentially malicious instructions embedded within the captures.
  • Capability inventory: The skill possesses the ability to edit local files, create new ones, and crucially, spawn a research-swarm sub-agent.
  • Sanitization: Raw content from the captures is directly interpolated into the prompt for the sub-agent in Step 7 (prompt="Research question: [Full capture content]"). A malicious note could contain instructions that hijack the research agent's mission.
  • [COMMAND_EXECUTION]: The skill instructions explicitly direct the agent to perform shell-based file operations.
  • Evidence: Step 1 requires the use of ls for file discovery, and Step 9 requires mv to relocate triaged files. If these are executed via a shell tool without proper escaping, a maliciously crafted filename (e.g., using semicolons or backticks) could lead to command injection on the host system.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:05 AM
Security Audit — agent-trust-hub — capture-triage