wiki-query
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill triggers the execution of a local script
python bin/generate-index.pyto maintain the wiki index. It also suggests and executesgit commitoperations for version-controlled wikis. - [INDIRECT_PROMPT_INJECTION]: The skill reads and processes external files (SCHEMA.md, wiki pages) which serve as potential vectors for indirect prompt injection.
- Ingestion points: Reads configuration from
SCHEMA.mdand content from individual wiki markdown files located inwiki/pages/. - Boundary markers: The skill lacks explicit delimiters or instructions to ignore embedded commands within the ingested wiki data, increasing the risk of the agent following instructions found inside the wiki pages.
- Capability inventory: The skill has the ability to execute shell commands (python, git) and write new files to the local file system.
- Sanitization: There is no evidence of sanitization, validation, or escaping of the content read from the wiki before it is synthesized into the final response or written back to the log.
Audit Metadata