research

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it processes content from an Obsidian vault that may contain malicious instructions.
  • Ingestion points: Vault data is ingested through obsidian_rag_query and obsidian_read_note as described in SKILL.md.
  • Boundary markers: There are no instructions to use delimiters or ignore instructions found within the retrieved note content.
  • Capability inventory: The skill uses tools for semantic search, note reading, and link traversal within the local file environment.
  • Sanitization: No sanitization or validation of note content is performed before the information is synthesized and presented to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 12:56 AM
Security Audit — agent-trust-hub — research