wiki-status

Warn

Audited by Gen Agent Trust Hub on Oct 6, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXPOSURE]: The skill accesses highly sensitive local directories and files to compute the wiki status and ingestion delta.
  • Globs ~/.claude/projects/ to read conversation logs (.jsonl) and memory files (.md).
  • Globs ~/.codex/ for session inventories and rollout transcripts.
  • Reads .env files during config resolution, which typically contain sensitive environment variables and API keys.
  • Reads vault pages for visibility/pii and visibility/internal tags to generate summary reports.
  • [COMMAND_EXECUTION]: The skill executes multiple local shell commands to perform analysis and vault maintenance.
  • Runs obsidian-wiki graph-analyse to perform degree ranking, community detection, and centrality analysis.
  • Runs ${QMD_CLI:-qmd} update and ${QMD_CLI:-qmd} embed to refresh search indexes and vector embeddings.
  • Executes audit passes for wiki-lint, wiki-dedup, cross-linker, and tag-taxonomy during equilibrium mode checks.
  • References the use of a local script scripts/manifest.py for manifest migrations.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data during its audit and reporting phases, creating a potential surface for indirect injection.
  • Ingestion points: Processes content from vault Markdown pages, Claude conversation histories, and Codex rollout transcripts (file paths: OBSIDIAN_VAULT_PATH, CLAUDE_HISTORY_PATH, CODEX_HISTORY_PATH).
  • Boundary markers: The instructions do not specify the use of explicit boundary markers or "ignore embedded instructions" warnings when aggregating content from these sources into the _insights.md or status reports.
  • Capability inventory: The agent has permissions to execute shell commands (obsidian-wiki, qmd) and write Markdown files (_insights.md, log.md) to the vault.
  • Sanitization: No explicit sanitization, escaping, or filtering of the processed external content is described before it is interpolated into the natural-language reports generated by the skill.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 6, 2026, 01:27 AM
Security Audit — agent-trust-hub — wiki-status