personal-siyuan-standards
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external configuration files and the user's personal SiYuan vault, creating an indirect prompt injection surface.
- Ingestion points: The agent reads placement mapping from map.md, tagging rules from tag.md, and existing note content from the SiYuan vault via the siyuan-note MCP tools.
- Boundary markers: The instructions do not specify the use of clear delimiters or boundary markers to distinguish user-provided note content from internal agent instructions.
- Capability inventory: The skill allows the agent to search, read, create, modify, move, and delete documents and blocks within the user's note-taking environment.
- Sanitization: Content retrieved from the vault or local files is not filtered or sanitized before being incorporated into the agent's reasoning context.
Audit Metadata