content-digest
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests untrusted data from external sources (YouTube transcripts, podcast content, and article URLs) using tools like WebFetch.
- Ingestion points: External content is fetched in Stage 1 of the workflow defined in
SKILL.md(Workflow Step 1). - Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded malicious prompts within the fetched content before processing.
- Capability inventory: The agent has the capability to write files to the local file system using a 'Write' tool as specified in the delivery section of
SKILL.md. - Sanitization: No explicit sanitization or filtering of the ingested external content is mentioned before it is interpolated into the summary generation process.
- [COMMAND_EXECUTION]: The skill explicitly directs the agent to use a 'Write' tool to save generated markdown files to a hardcoded local path:
/Users/ugreen/Documents/obsidian/每日播客/. While this supports the intended note-taking workflow, it involves the automated creation of files on the host system based on processed external content.
Audit Metadata