skills/ar9av/obsidian-wiki/llm-wiki/Gen Agent Trust Hub

llm-wiki

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process a wide variety of untrusted external data, including PDFs, web clippings, and conversation logs. Maliciously crafted content within these sources could attempt to influence the agent's behavior or corrupt the knowledge base during the distillation process.
  • Ingestion points: Files located in OBSIDIAN_SOURCES_DIR, the _raw/ staging directory, and various agent history paths (e.g., CLAUDE_HISTORY_PATH).
  • Boundary markers: The skill utilizes provenance markers (like ^[inferred]) in its output, but it does not specify explicit sanitization or boundary enforcement for input data during the ingestion phase.
  • Capability inventory: The skill performs file writes to the Obsidian vault and executes multiple shell-based tools including obsidian-wiki, qmd, and rg.
  • Sanitization: There are no instructions for sanitizing or escaping content from source files before it is processed by the LLM.
  • [COMMAND_EXECUTION]: The skill relies on and instructs the agent to execute several external CLI tools (obsidian-wiki, qmd, rg, grep, find, md5sum) to maintain the wiki structure, logs, and search indices. While these are necessary for the skill's functionality, improper handling of file paths or metadata passed to these commands could lead to unintended shell behavior if the inputs are not correctly escaped.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 10:15 AM
Security Audit — agent-trust-hub — llm-wiki