second-brain-ingest

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because its core function involves reading and summarizing untrusted content from the Clippings/ and raw/ directories.\n
  • Ingestion points: The skill ingests raw markdown files and web clippings that may contain attacker-controlled content.\n
  • Boundary markers: There are no explicit instructions or delimiters provided to the model to ignore or sequester instructions found within the source documents during the summarization and extraction process.\n
  • Capability inventory: The skill is authorized to use Bash, Read, Write, and Edit tools, allowing it to modify numerous files across the wiki/ directory based on the ingested content.\n
  • Sanitization: The skill implements an 'Author Sanitation' heuristic that rejects authors based on length, numeric patterns, or URL-like structures to maintain wiki integrity, but the main body content remains unsanitized against embedded LLM instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 05:07 PM
Security Audit — agent-trust-hub — second-brain-ingest