lisa-wiki-usage

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for ingesting untrusted external data into the repository's wiki, creating a surface for potential prompt injection attacks. * Ingestion points: The skill instructs the agent to ingest repository commits, merged pull requests, design plans, and meeting notes. * Boundary markers: There are no instructions for using delimiters or boundary markers to isolate external content. * Capability inventory: The agent is authorized to write to wiki files and perform git commit and push operations. * Sanitization: No sanitization or content validation steps are specified for the ingested data.
  • [NO_CODE]: This skill consists entirely of markdown documentation and YAML frontmatter. It does not include any executable scripts, binaries, or configuration files for package managers.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 06:27 AM
Security Audit — agent-trust-hub — lisa-wiki-usage