zettelkasten
Pass
Audited by Gen Agent Trust Hub on Jul 24, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a set of documentation and instructional guidelines for managing a knowledge base. It does not contain executable code, obfuscated payloads, or network-enabled operations.
- [COMMAND_EXECUTION]: The skill performs local file operations (reading, writing, and renaming markdown files) within a user-provided directory (
vault_path). These actions are necessary for the skill's stated purpose of note management. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided content such as literature excerpts and personal notes.
- Ingestion points: Data enters the system via the
vault_pathor text provided in the input contract (fleeting notes, literature content). - Boundary markers: The skill does not define explicit delimiters (like XML tags) for input data; however, it establishes a strict conceptual framework for processing input.
- Capability inventory: The skill manages files and creates/updates notes based on the processed content.
- Sanitization: The skill enforces a 'Own Words' (自己的話) principle, requiring the agent to rephrase and restructure input. This process acts as a form of natural sanitization against instructional structures embedded in source text.
Audit Metadata