write-a-wiki-page

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute build, test, and maintenance commands using pnpm, such as pnpm install --frozen-lockfile, pnpm generate, and pnpm turbo run check test build during the finalization steps.
  • [EXTERNAL_DOWNLOADS]: The skill performs network operations to fetch Git objects via pnpm sources:fetch and install project dependencies. These operations are scoped to the project's configured repositories (e.g., the 'rat-stack' repository) and standard package registries.
  • [INDIRECT_PROMPT_INJECTION]: There is a potential attack surface as the skill ingests content from various local directories (.brain/resources/lore/, .brain/areas/, skills/) to generate wiki pages.
  • Ingestion points: Files located in .brain/ and skills/ directories (SKILL.md, step 1).
  • Boundary markers: The skill uses YAML frontmatter and Markdown code fences to delimit different content types.
  • Capability inventory: The agent has the ability to run shell commands via pnpm for building, testing, and generating static assets.
  • Sanitization: The skill provides strict formatting rules (Simplified Technical English, specific sentence length limits) which act as a natural filter for anomalous content.
  • [SAFE]: The instructions include explicit security guardrails, warning the agent to keep private paths, host names, credentials, and customer data out of generated pages and code examples.
  • [SAFE]: The skill implements integrity checks by requiring 40-character commit SHAs for code snippets to ensure that the quoted code matches a specific, immutable version of the source repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 01:57 AM
Security Audit — agent-trust-hub — write-a-wiki-page