content-digest

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests untrusted data from external sources (YouTube transcripts, podcast content, and article URLs) using tools like WebFetch.
  • Ingestion points: External content is fetched in Stage 1 of the workflow defined in SKILL.md (Workflow Step 1).
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded malicious prompts within the fetched content before processing.
  • Capability inventory: The agent has the capability to write files to the local file system using a 'Write' tool as specified in the delivery section of SKILL.md.
  • Sanitization: No explicit sanitization or filtering of the ingested external content is mentioned before it is interpolated into the summary generation process.
  • [COMMAND_EXECUTION]: The skill explicitly directs the agent to use a 'Write' tool to save generated markdown files to a hardcoded local path: /Users/ugreen/Documents/obsidian/每日播客/. While this supports the intended note-taking workflow, it involves the automated creation of files on the host system based on processed external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 02:09 AM