siyuan

Warn

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection attacks because it reads untrusted content from the knowledge base and has significant modification capabilities.
  • Ingestion points: Data is retrieved via endpoints such as /api/block/getBlockKramdown, /api/search/fullTextSearchBlock, and /api/query/sql (SKILL.md).
  • Boundary markers: There are no explicit instructions or delimiters to isolate content retrieved from the API, leaving the agent vulnerable to instructions embedded within notes.
  • Capability inventory: The skill provides commands to perform sensitive operations including /api/block/updateBlock, /api/block/deleteBlock, and /api/filetree/removeDocByID (SKILL.md).
  • Sanitization: No validation or sanitization of retrieved data is described.
  • [EXTERNAL_DOWNLOADS]: The skill documents the installation and execution of a third-party Node.js package from an unverified source.
  • Evidence: The "Alternative: MCP Server" section recommends installing @porkll/siyuan-mcp using npx -y.
  • [COMMAND_EXECUTION]: The skill instructions rely on the agent executing shell commands (curl, jq) which process user-controlled environment variables and parameters.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 2, 2026, 04:03 PM