daily-work-diary
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external sources such as calendars, task lists, and Git activity logs via authorized tools. This creates an attack surface where malicious content embedded in those external sources could attempt to influence the agent's behavior during the reflection process.
- [DATA_EXPOSURE]: The skill intentionally requests access to potentially sensitive information (work episodes, commits, calendar events). While the instructions include explicit privacy guardrails (e.g., 'Never capture secrets', 'Do not access... without explicit scope'), the capability to process sensitive data remains a core function that requires user trust in the underlying tools.
- [SAFE]: No obfuscation, hardcoded credentials, or unauthorized remote code execution patterns were detected in the provided skill files.
Audit Metadata