wiki-ingest
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local Python script
python bin/generate-index.py(Step 8) to regenerate the wiki index based on newly ingested content. This relies on the existence of a script within the project's directory structure. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external URLs, local files, or pasted text to perform a multi-page update across the wiki, including summaries and entity descriptions.
- Ingestion points: Untrusted data enters the agent context through the
browseskill for URLs, direct file reads, or user-pasted text (Step 1). - Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are specified when processing the ingested content.
- Capability inventory: The skill can write and modify multiple markdown files (
wiki/pages/*.md,wiki/log.md,wiki/overview.md) and execute a local Python script (bin/generate-index.py). - Sanitization: No sanitization, validation, or escaping of the external content is performed before it is synthesized into the wiki structure.
Audit Metadata