soia-media-compose-article-draft

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting and processing untrusted content from the user's Obsidian vault without using explicit delimiters or instructions to ignore embedded commands. Ingestion points: Reads from '00_Obsidian系统/个人说明书.md' and viewpoint summary files in the '50_草稿/' directory. Boundary markers: Absent. The instructions do not define delimiters to separate processed data from instructions. Capability inventory: File read and write access within the Obsidian vault. Sanitization: None detected in the instructions for handling external text snippets.
  • [DATA_EXFILTRATION]: The skill is instructed to access and read personal files within the Obsidian vault, such as '00_Obsidian系统/个人说明书.md', to determine the user's reader and tone positioning. While this is the intended functionality, it represents the exposure of local user data to the agent's context.
  • [EXTERNAL_DOWNLOADS]: The skill documentation recommends installing external packages and plugins via 'npx' and the 'claude' CLI. These resources, such as 'soia-team/soia-open-media-content-skills', are hosted on public registries and GitHub under the author organization 'soia-team'.
  • [SAFE]: The skill follows secure practices for handling credentials, explicitly instructing that secrets like API keys, cookies, or sessions must only be stored in private configuration files (config.yml) or environment variables and never in logs, the vault, or the repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 08:47 AM
Security Audit — agent-trust-hub — soia-media-compose-article-draft