wiki-architect
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it ingests and processes untrusted repository data.
- Ingestion points: The skill instructions direct the agent to scan the repository file tree and README content (
SKILL.md). - Boundary markers: There are no instructions to use delimiters or ignore potential commands embedded within the repository content being analyzed.
- Capability inventory: The skill is limited to generating a hierarchical JSON catalogue and citing file paths; it does not explicitly invoke high-risk tools for network access or system modification.
- Sanitization: There is no mention of filtering or sanitizing the ingested repository data before it is incorporated into the documentation plan.
Audit Metadata