llm-wiki
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process a wide variety of untrusted external data, including PDFs, web clippings, and conversation logs. Maliciously crafted content within these sources could attempt to influence the agent's behavior or corrupt the knowledge base during the distillation process.
- Ingestion points: Files located in
OBSIDIAN_SOURCES_DIR, the_raw/staging directory, and various agent history paths (e.g.,CLAUDE_HISTORY_PATH). - Boundary markers: The skill utilizes provenance markers (like
^[inferred]) in its output, but it does not specify explicit sanitization or boundary enforcement for input data during the ingestion phase. - Capability inventory: The skill performs file writes to the Obsidian vault and executes multiple shell-based tools including
obsidian-wiki,qmd, andrg. - Sanitization: There are no instructions for sanitizing or escaping content from source files before it is processed by the LLM.
- [COMMAND_EXECUTION]: The skill relies on and instructs the agent to execute several external CLI tools (
obsidian-wiki,qmd,rg,grep,find,md5sum) to maintain the wiki structure, logs, and search indices. While these are necessary for the skill's functionality, improper handling of file paths or metadata passed to these commands could lead to unintended shell behavior if the inputs are not correctly escaped.
Audit Metadata