Evernote Hello WorldSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: evernote-hello-world description: 'Create a minimal working Evernote example. Use when starting a new Evernote integration, testing your setup, or learning basic Evernote API patterns. Trigger with phrases like "evernote hello world", "evernote example", "evernote quick start", "simple evernote code", "create first note". ' allowed-tools: Read, Write, Edit version: 1.13.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - evernote - api - testing compatibility: Designed for Claude Code --- # Evernote Hello World ## Overview Create your first Evernote note using the Cloud API, demonstrating ENML format and NoteStore operations. ## Prerequisites - Completed `evernote-install-auth` setup - Valid access token (OAuth or Developer Token for sandbox) - Development environment ready ## Instructions ### Step 1: Create Entry File Initialize an authenticated Evernote client. Use a Developer Token for sandbox or an OAuth access token for production. ```javascript // hello-evernote.js const Evernote = require('evernote'); const client = new Evernote.Client({ token: process.env.EVERNOTE_ACCESS_TOKEN, sandbox: true // false for production }); ``` ### Step 2: Understand ENML Format Evernote uses ENML (Evernote Markup Language), a restricted XHTML subset. Every note must include the XML declaration, DOCTYPE, and `<en-note>` root element. Forbidden elements include `<script>`, `<form>`, `<iframe>`. Only inline styles are allowed (no `class` or `id` attributes). ```xml <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE en-note SYSTEM "http://xml.evernote.com/pub/enml2.dtd"> <en-note> <h1>Note Title</h1> <p>Content goes here</p> <en-todo checked="false"/> A task item </en-note> ``` ### Step 3: Create Your First Note Build ENML content and call `noteStore.createNote()`. The returned object contains the `guid`, `title`, and `created` timestamp. ```javascript async function createHelloWorldNote() { const noteStore = client.getNoteStore(); const content = `<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE en-note SYSTEM "http://xml.evernote.com/pub/enml2.dtd"> <en-note> <h1>Hello from Claude Code!</h1> <p>Created at: ${new Date().toISOString()}</p> </en-note>`; const note = new Evernote.Types.Note(); note.title = 'Hello World - Evernote API'; note.content = content; const createdNote = await noteStore.createNote(note); console.log('Note GUID:', createdNote.guid); return createdNote; } ``` ### Step 4: List Notebooks and Retrieve Notes Use `listNotebooks()` to enumerate notebooks and `getNote()` with boolean flags to control what data is returned (content, resources, recognition, alternate data). ```javascript const noteStore = client.getNoteStore(); // List all notebooks const notebooks = await noteStore.listNotebooks(); notebooks.forEach(nb => console.log(`- ${nb.name} (${nb.guid})`)); // Retrieve a note with content const note = await noteStore.getNote(noteGuid, true, false, false, false); console.log('Title:', note.title); ``` For the complete working example with Python SDK, todo lists, and a combined workflow, see [Implementation Guide](references/implementation-guide.md). ## Output - Working code file with Evernote client initialization - Successfully created note in your Evernote account - Console output with note GUID and confirmation ## Error Handling | Error | Cause | Solution | |-------|-------|----------| | `EDAMUserException: BAD_DATA_FORMAT` | Invalid ENML content | Validate against ENML DTD; ensure XML declaration and DOCTYPE | | `EDAMNotFoundException` | Note or notebook not found | Check GUID is correct and note is not in trash | | `EDAMSystemException: RATE_LIMIT_REACHED` | Too many requests | Wait for `rateLimitDuration` seconds before retrying | | `Missing DOCTYPE` | ENML missing required header | Add `<?xml ...?>` and `<!DOCTYPE ...>` before `<en-note>` | ## Resources - [Creating Notes](https://dev.evernote.com/doc/articles/creating_notes.php) - [ENML Reference](https://dev.evernote.com/doc/articles/enml.php) - [Core Concepts](https://dev.evernote.com/doc/articles/core_concepts.php) - [API Reference](https://dev.evernote.com/doc/reference/) ## Next Steps Proceed to `evernote-local-dev-loop` for development workflow setup. ## Examples **Sandbox test**: Create a note using a Developer Token with `sandbox: true`, verify it appears in your sandbox account at `sandbox.evernote.com`. **Production note**: Switch to OAuth access token, set `sandbox: false`, create a note in a specific notebook using `note.notebookGuid`.
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__evernote-hello-world.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Evernote Hello World skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Evernote Hello World safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Evernote Hello World access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Evernote Hello World work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.