wiki-narrate

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill is designed to operate exclusively on local files within an Obsidian vault, with no evidence of network operations, credential harvesting, or data exfiltration attempts.
  • [COMMAND_EXECUTION]: The skill utilizes ripgrep (rg) and a vault-specific tool (QMD) for indexing and searching content. These are standard, low-privilege tools used for the skill's primary purpose of information retrieval.
  • [PROMPT_INJECTION]: The skill implements strong defensive instructions that protect against indirect prompt injection. It mandates the exclusion of pages with internal or PII tags and requires all factual claims to be strictly supported by vault citations, effectively preventing the agent from following potentially malicious instructions embedded in vault content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 06:53 AM
Security Audit — agent-trust-hub — wiki-narrate