vault-today
Pass
Audited by Gen Agent Trust Hub on Feb 25, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted user data from local markdown files in an Obsidian vault, which presents an indirect prompt injection surface.
- Ingestion points: Reads markdown files from
~/Documents/vault-notes/02. Area/Daily Notes/and files tagged with#priorityor#focus. - Boundary markers: None specified to distinguish note content from instructions.
- Capability inventory: File system read access to the vault and write access to create/update daily journal files.
- Sanitization: No sanitization of the markdown content is performed before processing.
Audit Metadata