skills/deepparser/skills/llm-wiki/Gen Agent Trust Hub

llm-wiki

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted documents from the raw/ directory to build the wiki, which presents an attack surface for indirect prompt injection. Maliciously crafted source documents could influence the agent's behavior during ingestion or querying.
  • Ingestion points: Files in the raw/ directory read during the Ingest and Query operations defined in SKILL.md.
  • Boundary markers: The skill uses YAML frontmatter and structured Markdown but lacks explicit instructions to ignore or delimit embedded commands within source documents.
  • Capability inventory: File system read/write operations (Markdown and logs) in SKILL.md and local shell execution in scripts/init-wiki.sh.
  • Sanitization: No specific sanitization, filtering, or validation of the content within ingested source documents is mentioned.
  • [COMMAND_EXECUTION]: The skill includes a bash script scripts/init-wiki.sh used to initialize the wiki's directory structure and initial files.
  • The script uses standard shell utilities such as mkdir, cat, and sed to operate on the local file system.
  • While standard for setup, the script accepts user-provided arguments for the wiki name and base directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:53 AM
Security Audit — agent-trust-hub — llm-wiki