archive
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [Indirect Prompt Injection] (LOW): The skill reads and processes the content of user-defined files in '20_项目/' and '00_收件箱/', which could contain instructions intended to subvert the agent's behavior. Ingestion points: File content reading occurs in the 'Archive Process' workflow. Boundary markers: Absent; the skill does not use delimiters or instructions to ignore embedded commands within the files being processed. Capability inventory: The agent can move files, modify YAML frontmatter, and update daily notes. Sanitization: No content validation or sanitization is performed.
- [No Code] (SAFE): The skill consists entirely of instructional markdown and does not include executable scripts or external dependencies.
Audit Metadata