docs-notes-retrieval
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from user-provided note vaults, creating a potential surface for indirect prompt injection attacks.\n- Ingestion points: Markdown files are read from local directories by scripts/scan_vault.py and scripts/build_context_pack.py.\n- Boundary markers: The ContextPackBuilder.build() method in scripts/build_context_pack.py delimits note content using markdown headers, metadata blocks, and horizontal rules.\n- Capability inventory: The scripts perform local file system read/write operations and lack network or shell execution capabilities.\n- Sanitization: Note content is included verbatim in the context bundle without filtering for instructions that might target the consuming AI agent.
Audit Metadata