soia-pkm-clip-drive

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill operates on untrusted external data, presenting an indirect prompt injection surface.
  • Ingestion points: Processes PDF, DOCX, TXT, and Markdown files using pypdf, pdfplumber, and python-docx (SKILL.md).
  • Boundary markers: There are no explicit markers or instructions defined to prevent the agent from following directions potentially embedded within the processed documents.
  • Capability inventory: The skill is capable of reading from user-specified file paths and writing to the Obsidian vault.
  • Sanitization: No content filtering or validation for the extracted text is mentioned in the instructions.
  • [EXTERNAL_DOWNLOADS]: The documentation provides an installation command for a package from the author's organization.
  • Evidence: npx skills add soia-team/soia-open-pkm-clip-skills (SKILL.md). This corresponds to a vendor-owned resource.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 01:49 PM
Security Audit — agent-trust-hub — soia-pkm-clip-drive