synthesize-wiki
Pass
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill utilizes a pattern of reading and aggregating content from multiple user-provided source notes to generate new wiki entries. This behavior introduces a surface for indirect prompt injection.
- Ingestion points: The agent is instructed to read all markdown files (
Source -- *.md) identified as relevant to the topic. - Boundary markers: No specific delimiters or "ignore instructions" warnings are implemented to protect the agent from adversarial commands embedded within the vault files.
- Capability inventory: The skill allows access to
Bash,Read,Write, andEdittools, which could be leveraged if the agent inadvertently follows instructions found in source material. - Sanitization: There is no evidence of sanitization or filtering of external content before it is interpolated into the agent's context for processing.
- [SAFE]: The Bash workflow includes a hardcoded local file path (
/Users/ethanphan/Documents/my-obsidian-v1) as a default for the Obsidian vault. This represents a minor exposure of local environment metadata (username) but does not involve network operations or exfiltration of sensitive information.
Audit Metadata