wiki-query
Pass
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes content from a user's Obsidian wiki, which represents a surface for indirect prompt injection if the wiki contains instructions designed to manipulate the agent.
- Ingestion points: The skill reads page summaries, frontmatter, and full page bodies (Steps 2-4) from the local vault directory.
- Boundary markers: The skill includes a clear 'This skill is READ-ONLY' section and explicit instructions to only propose changes rather than execute them, which serves as a behavioral boundary for the agent.
- Capability inventory: The skill utilizes shell-based tools including
obsidian-wiki,qmd, andgrep. It has the ability to append to a log file (log.md) via theobsidian-wiki memory logcommand. - Sanitization: No explicit sanitization or escaping of the wiki content is mentioned before it is processed by the LLM.
- [COMMAND_EXECUTION]: The skill relies on executing external CLI tools (
obsidian-wikiandqmd) to perform graph queries and semantic searches. While these are core to the skill's functionality, they involve spawning subprocesses using paths derived from environment variables likeOBSIDIAN_VAULT_PATHandQMD_CLI.
Audit Metadata