crossframe-notebook
Pass
Audited by Gen Agent Trust Hub on Jul 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of markdown documentation, templates, and configuration files intended to guide an AI agent in structured note-taking. No executable code or scripts are included.
- [PROMPT_INJECTION]: The instructions do not contain any patterns attempting to override safety guardrails, bypass ethical filters, or extract system prompts. On the contrary, the instructions repeatedly emphasize honesty, source verification, and avoiding the fabrication of citations.
- [DATA_EXFILTRATION]: There are no network requests, API calls, or attempts to access sensitive system files (e.g., SSH keys, environment variables). The skill operates solely on the text provided in the user context.
- [REMOTE_CODE_EXECUTION]: No remote scripts are downloaded or executed. The skill does not use package managers or dynamic execution environments.
- [INDIRECT_PROMPT_INJECTION]: While the skill is designed to process untrusted external data (books, articles, excerpts), it includes robust procedural safeguards. The
protocols/source-integrity-protocol.mdandreferences/source-boundary-rules.mdfiles provide detailed instructions for the agent to categorize source reliability and explicitly label转述 (paraphrasing) vs. direct quotes. There are no capabilities (like shell access or network tools) that could be exploited via data ingestion. (Severity: LOW). - [METADATA_POISONING]: The metadata matches the functionality of the skill. While there is a minor discrepancy between the author listed in the metadata (xi-kari) and the vendor context provided (sickn33), this is common in template reuse and presents no security risk.
Audit Metadata