skills/karlorz/llm-wiki/wiki-query/Gen Agent Trust Hub

wiki-query

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill contains no malicious patterns and proactively implements security measures to protect user data.
  • [COMMAND_EXECUTION]: The agent is instructed to use diagnostic commands (e.g., checking file existence, using grep on configurations, or inspecting crontabs) to verify system state, ensuring that documentation in the vault matches the actual filesystem.
  • [PROMPT_INJECTION]: The skill manages an indirect prompt injection surface where it reads vault content. It mitigates risk through a 'Sensitive content guard' in Step 7 and a verification mandate in the 'Pitfalls' section.
  • [PROMPT_INJECTION]: Ingestion points: Vault contents are read from files in Step 5.
  • [PROMPT_INJECTION]: Boundary markers: Absent.
  • [PROMPT_INJECTION]: Capability inventory: Uses the skillwiki CLI and standard diagnostic shell commands.
  • [PROMPT_INJECTION]: Sanitization: The skill redacts credentials and requires verification of claims against the filesystem to prevent the agent from following misleading data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 11:30 AM
Security Audit — agent-trust-hub — wiki-query