okf-wiki
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests external data to generate concepts. 1. Ingestion points: SKILL.md. 2. Boundary markers: Absent during raw data gathering. 3. Capability inventory: scripts/scaffold.py (file system write) and scripts/gh-wiki-bootstrap.py (browser automation). 4. Sanitization: Present via manual stripping instructions and the scripts/validate.py scanner.\n- [COMMAND_EXECUTION]: The skill executes self-validation commands. Evidence: scripts/scaffold.py calls scripts/validate.py using subprocess.run.\n- [PERSISTENCE]: The orientation gate tracks state across sessions. Evidence: okf-orient.py writes markers to the user's private cache directory (~/.cache/okf-orient/).
Audit Metadata