wiki-update

Warn

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains potential command injection vulnerabilities. It interpolates values from .manifest.json (such as last_commit_synced) directly into shell commands like git merge-base --is-ancestor <last_commit_synced> HEAD and obsidian-wiki code-understand ... --since <last_commit_synced>. If the manifest file is compromised, an attacker could execute arbitrary commands. Additionally, the skill executes various local tools including git, obsidian-wiki, and qmd.
  • [EXTERNAL_DOWNLOADS]: The skill instructions direct the agent to offer the installation of the external NPM package @colbymchenry/codegraph to the user, which is a third-party dependency not associated with the skill author.
  • [DATA_EXFILTRATION]: The skill accesses sensitive configuration files, specifically walking up the directory tree to find and read .env files to resolve vault paths and other settings.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted project content, creating an indirect prompt injection surface.
  • Ingestion points: Reads README, documentation, source code structure, git logs, and Claude memory files from the current project directory.
  • Boundary markers: No delimiters or safety instructions are specified to prevent the agent from following instructions embedded in project files.
  • Capability inventory: The skill can write to the user's filesystem (Obsidian vault) and execute shell commands via git and other tools.
  • Sanitization: There is no mention of sanitizing or validating the extracted information before it is written to the wiki.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 23, 2026, 04:52 PM
Security Audit — agent-trust-hub — wiki-update