research

Pass

Audited by Gen Agent Trust Hub on Jul 26, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data from repository files during the research process (Ingestion point: SKILL.md). The skill lacks explicit boundary markers or system instructions to disregard instructions embedded within the files it analyzes. It possesses the capability to write to local storage (Capability: obsidian_append_content tool usage in SKILL.md). No sanitization or filtering of the external repository content is implemented.
  • [COMMAND_EXECUTION]: The skill utilizes the dynamic context injection pattern (!date) in SKILL.md. The command is used to include the current timestamp at load time. While this specific instance is functional for logging, the syntax represents an execution surface for shell commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 26, 2026, 12:10 AM
Security Audit — agent-trust-hub — research