synthesize-wiki

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill utilizes a pattern of reading and aggregating content from multiple user-provided source notes to generate new wiki entries. This behavior introduces a surface for indirect prompt injection.
  • Ingestion points: The agent is instructed to read all markdown files (Source -- *.md) identified as relevant to the topic.
  • Boundary markers: No specific delimiters or "ignore instructions" warnings are implemented to protect the agent from adversarial commands embedded within the vault files.
  • Capability inventory: The skill allows access to Bash, Read, Write, and Edit tools, which could be leveraged if the agent inadvertently follows instructions found in source material.
  • Sanitization: There is no evidence of sanitization or filtering of external content before it is interpolated into the agent's context for processing.
  • [SAFE]: The Bash workflow includes a hardcoded local file path (/Users/ethanphan/Documents/my-obsidian-v1) as a default for the Obsidian vault. This represents a minor exposure of local environment metadata (username) but does not involve network operations or exfiltration of sensitive information.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 01:51 PM
Security Audit — agent-trust-hub — synthesize-wiki