wiki-update
Warn
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill contains potential command injection vulnerabilities. It interpolates values from
.manifest.json(such aslast_commit_synced) directly into shell commands likegit merge-base --is-ancestor <last_commit_synced> HEADandobsidian-wiki code-understand ... --since <last_commit_synced>. If the manifest file is compromised, an attacker could execute arbitrary commands. Additionally, the skill executes various local tools includinggit,obsidian-wiki, andqmd. - [EXTERNAL_DOWNLOADS]: The skill instructions direct the agent to offer the installation of the external NPM package
@colbymchenry/codegraphto the user, which is a third-party dependency not associated with the skill author. - [DATA_EXFILTRATION]: The skill accesses sensitive configuration files, specifically walking up the directory tree to find and read
.envfiles to resolve vault paths and other settings. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted project content, creating an indirect prompt injection surface.
- Ingestion points: Reads README, documentation, source code structure, git logs, and Claude memory files from the current project directory.
- Boundary markers: No delimiters or safety instructions are specified to prevent the agent from following instructions embedded in project files.
- Capability inventory: The skill can write to the user's filesystem (Obsidian vault) and execute shell commands via
gitand other tools. - Sanitization: There is no mention of sanitizing or validating the extracted information before it is written to the wiki.
Audit Metadata