skills/kfchou/wiki-skills/wiki-ingest/Gen Agent Trust Hub

wiki-ingest

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local Python script python bin/generate-index.py (Step 8) to regenerate the wiki index based on newly ingested content. This relies on the existence of a script within the project's directory structure.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external URLs, local files, or pasted text to perform a multi-page update across the wiki, including summaries and entity descriptions.
  • Ingestion points: Untrusted data enters the agent context through the browse skill for URLs, direct file reads, or user-pasted text (Step 1).
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are specified when processing the ingested content.
  • Capability inventory: The skill can write and modify multiple markdown files (wiki/pages/*.md, wiki/log.md, wiki/overview.md) and execute a local Python script (bin/generate-index.py).
  • Sanitization: No sanitization, validation, or escaping of the external content is performed before it is synthesized into the wiki structure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:42 PM
Security Audit — agent-trust-hub — wiki-ingest