siyuan
Warn
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection attacks because it reads untrusted content from the knowledge base and has significant modification capabilities.
- Ingestion points: Data is retrieved via endpoints such as
/api/block/getBlockKramdown,/api/search/fullTextSearchBlock, and/api/query/sql(SKILL.md). - Boundary markers: There are no explicit instructions or delimiters to isolate content retrieved from the API, leaving the agent vulnerable to instructions embedded within notes.
- Capability inventory: The skill provides commands to perform sensitive operations including
/api/block/updateBlock,/api/block/deleteBlock, and/api/filetree/removeDocByID(SKILL.md). - Sanitization: No validation or sanitization of retrieved data is described.
- [EXTERNAL_DOWNLOADS]: The skill documents the installation and execution of a third-party Node.js package from an unverified source.
- Evidence: The "Alternative: MCP Server" section recommends installing
@porkll/siyuan-mcpusingnpx -y. - [COMMAND_EXECUTION]: The skill instructions rely on the agent executing shell commands (
curl,jq) which process user-controlled environment variables and parameters.
Audit Metadata