llm-wiki

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: HIGHPRIVILEGE_ESCALATIONPERSISTENCECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill instructs the user to execute sudo loginctl enable-linger $USER to maintain background synchronization processes after logging out.- [PERSISTENCE]: Detailed instructions are provided for creating a systemd user service (obsidian-wiki-sync.service) and enabling it with systemctl, ensuring the wiki sync tool remains active across user sessions and system restarts.- [CREDENTIALS_UNSAFE]: The documentation for obsidian-headless setup includes the command ob login --email <email> --password '<password>', which encourages users to pass sensitive credentials as plaintext arguments in the terminal where they may be logged in shell history or visible to other users.- [EXTERNAL_DOWNLOADS]: The skill recommends installing the obsidian-headless package via npm and references the llm-wiki-compiler tool hosted in an external GitHub repository.- [COMMAND_EXECUTION]: The instructions provide multiple shell commands for global package installation and system service management.- [DYNAMIC_EXECUTION]: The linting operation utilizes execute_code to run Python scripts that scan the filesystem for orphan pages and link integrity.- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted external data from web articles and PDFs via web_extract to build a synthesis of knowledge.
  • Ingestion points: External source materials are fetched and stored in the raw/ subdirectory.
  • Boundary markers: The skill uses YAML frontmatter and provenance markers in the generated markdown, but lacks explicit delimiters or safety instructions to the model to ignore potential malicious instructions embedded within the ingested raw content.
  • Capability inventory: The skill uses execute_code for programmatic tasks, file read/write operations, and shell command execution for setup.
  • Sanitization: There is no mentioned validation or sanitization of external content before it is processed by the agent for knowledge synthesis.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 15, 2026, 01:21 PM