wiki-cli

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from user-defined Obsidian vaults. It mitigates risk by requiring the agent to reject absolute note arguments, directory traversal, symlinks, and paths resolved outside the selected vault context.
  • [COMMAND_EXECUTION]: The skill utilizes local shell scripts and the obsidian CLI binary for vault discovery and data retrieval. These operations are scoped to the local environment and the predefined product root, with mutations explicitly forbidden to ensure safety.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 04:51 PM
Security Audit — agent-trust-hub — wiki-cli