llm-wiki
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: HIGHPRIVILEGE_ESCALATIONPERSISTENCECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill instructs the user to execute
sudo loginctl enable-linger $USERto maintain background synchronization processes after logging out.- [PERSISTENCE]: Detailed instructions are provided for creating asystemduser service (obsidian-wiki-sync.service) and enabling it withsystemctl, ensuring the wiki sync tool remains active across user sessions and system restarts.- [CREDENTIALS_UNSAFE]: The documentation forobsidian-headlesssetup includes the commandob login --email <email> --password '<password>', which encourages users to pass sensitive credentials as plaintext arguments in the terminal where they may be logged in shell history or visible to other users.- [EXTERNAL_DOWNLOADS]: The skill recommends installing theobsidian-headlesspackage via npm and references thellm-wiki-compilertool hosted in an external GitHub repository.- [COMMAND_EXECUTION]: The instructions provide multiple shell commands for global package installation and system service management.- [DYNAMIC_EXECUTION]: The linting operation utilizesexecute_codeto run Python scripts that scan the filesystem for orphan pages and link integrity.- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted external data from web articles and PDFs viaweb_extractto build a synthesis of knowledge. - Ingestion points: External source materials are fetched and stored in the
raw/subdirectory. - Boundary markers: The skill uses YAML frontmatter and provenance markers in the generated markdown, but lacks explicit delimiters or safety instructions to the model to ignore potential malicious instructions embedded within the ingested raw content.
- Capability inventory: The skill uses
execute_codefor programmatic tasks, file read/write operations, and shell command execution for setup. - Sanitization: There is no mentioned validation or sanitization of external content before it is processed by the agent for knowledge synthesis.
Recommendations
- AI detected serious security threats
Audit Metadata