second-brain-query
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and synthesize data from user-provided files within a knowledge base.
- Ingestion points: The skill reads from
wiki/index.md,wiki/sources/, and files within theraw/directory. - Boundary markers: There are no explicit instructions or delimiters used to ensure the agent ignores malicious instructions that might be embedded within the wiki files.
- Capability inventory: The skill utilizes
Bash,Read,Write,Edit,Glob, andGreptools, which could be leveraged if an injection is successful. - Sanitization: No sanitization or validation of the content read from the wiki is performed before it is processed by the agent.
- [COMMAND_EXECUTION]: The instructions direct the agent to execute shell commands to perform searches.
- Evidence: The skill checks for the existence of a utility using
command -v qmdand executes searches usingqmd search "query terms" --path wiki/. This is standard functionality for the skill's intended purpose.
Audit Metadata