skills/ar9av/obsidian-wiki/wiki-query/Gen Agent Trust Hub

wiki-query

Pass

Audited by Gen Agent Trust Hub on Oct 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes content from a user's Obsidian wiki, which represents a surface for indirect prompt injection if the wiki contains instructions designed to manipulate the agent.
  • Ingestion points: The skill reads page summaries, frontmatter, and full page bodies (Steps 2-4) from the local vault directory.
  • Boundary markers: The skill includes a clear 'This skill is READ-ONLY' section and explicit instructions to only propose changes rather than execute them, which serves as a behavioral boundary for the agent.
  • Capability inventory: The skill utilizes shell-based tools including obsidian-wiki, qmd, and grep. It has the ability to append to a log file (log.md) via the obsidian-wiki memory log command.
  • Sanitization: No explicit sanitization or escaping of the wiki content is mentioned before it is processed by the LLM.
  • [COMMAND_EXECUTION]: The skill relies on executing external CLI tools (obsidian-wiki and qmd) to perform graph queries and semantic searches. While these are core to the skill's functionality, they involve spawning subprocesses using paths derived from environment variables like OBSIDIAN_VAULT_PATH and QMD_CLI.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 6, 2026, 06:11 AM
Security Audit — agent-trust-hub — wiki-query