vault-journal
Pass
Audited by Gen Agent Trust Hub on Apr 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs local note-taking operations within an Obsidian vault using the
obsidianCLI tool. All actions are consistent with the skill's description and intended research-logging purpose. - [COMMAND_EXECUTION]: The skill utilizes command-line tools for note management tasks. No evidence of arbitrary command execution, privilege escalation, or persistence mechanisms was found.
- [PROMPT_INJECTION]: The skill processes untrusted user data (Ingestion points: user entry content). It lacks explicit boundary markers for the data. Its capabilities include file modification via the
obsidianCLI (Capability inventory: obsidian daily:append, obsidian create). The agent is instructed to summarize and clean the text (Sanitization: summarization and cleanup instructions).
Audit Metadata