wiki-lint
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes local Python scripts, specifically
bin/generate-index.pyandbin/lint-mechanical.py, to manage the wiki index and execute deterministic linting rules. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted wiki content which could contain instructions designed to manipulate the behavior of the subagents or the resulting audit report.
- Ingestion points: Wiki page bodies,
SCHEMA.md, and configuration files likeconfig/link-style.mdare read and processed during various phases of the audit. - Boundary markers: The skill provides scope-limiting instructions to subagents, but it does not employ structural delimiters (such as XML tags or unique markers) around the untrusted content to prevent the LLM from following embedded instructions.
- Capability inventory: The agent can execute local scripts, write or modify markdown files within the wiki directory, and perform Git operations (commits) or log file updates.
- Sanitization: There is no evidence of content sanitization, regex filtering, or escaping of wiki data before it is presented to the LLM for analysis.
Audit Metadata