skills/ethan-rio/skills/update-index/Gen Agent Trust Hub

update-index

Warn

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The Bash script in SKILL.md is vulnerable to path traversal. It uses the $ARGUMENTS variable directly to construct the WIKI_PATH without sanitizing for directory traversal sequences like ../. This allows an attacker to force the script to read files outside the intended Obsidian vault.
  • [DATA_EXFILTRATION]: The script reads the contents of files specified via $ARGUMENTS. If a user is tricked into providing a path to a sensitive file (e.g., ../../.ssh/config), the script will attempt to parse it for tags, potentially exposing the existence or structure of sensitive local data in the error logs or resulting index updates.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection. It parses the tags field from a note's frontmatter to determine which index files to modify. If a note contains a maliciously crafted tag such as ../../etc/cron.d/malicious, the script may attempt to write content to that path during the index update process.
  • [CREDENTIALS_UNSAFE]: The script contains a hardcoded local filesystem path: /Users/ethanphan/Documents/my-obsidian-v1. While not a credential, this exposes the user's local username and internal directory structure, which can be used to facilitate more targeted attacks.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 18, 2026, 01:50 PM
Security Audit — agent-trust-hub — update-index