llm-wiki
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted documents from the
raw/directory to build the wiki, which presents an attack surface for indirect prompt injection. Maliciously crafted source documents could influence the agent's behavior during ingestion or querying. - Ingestion points: Files in the
raw/directory read during the Ingest and Query operations defined inSKILL.md. - Boundary markers: The skill uses YAML frontmatter and structured Markdown but lacks explicit instructions to ignore or delimit embedded commands within source documents.
- Capability inventory: File system read/write operations (Markdown and logs) in
SKILL.mdand local shell execution inscripts/init-wiki.sh. - Sanitization: No specific sanitization, filtering, or validation of the content within ingested source documents is mentioned.
- [COMMAND_EXECUTION]: The skill includes a bash script
scripts/init-wiki.shused to initialize the wiki's directory structure and initial files. - The script uses standard shell utilities such as
mkdir,cat, andsedto operate on the local file system. - While standard for setup, the script accepts user-provided arguments for the wiki name and base directory.
Audit Metadata