wiki-builder
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/init_wiki.shscript uses thesedutility to render wiki templates. Thetitlevariable is interpolated directly into asedcommand string without sanitizing the delimiter character (|). An attacker providing a crafted title could inject additionalsedcommands, potentially causing the script to write content to unauthorized file paths or manipulate the generated wiki configuration. - [DATA_EXFILTRATION]: The
scripts/wiki-cli.jstool provides apagecommand that accepts a--from-fileargument. This functionality allows the agent to read any file from the host system and store its content within the wiki's structure. If misused, this could lead to the exposure of sensitive local files, such as SSH keys, API credentials, or environment configurations, by indexing them in the wiki's searchable database. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize external source materials (PDFs, web scrapes, transcripts) stored in a
raw/directory. This creates a surface for indirect prompt injection where malicious instructions embedded in these sources could be executed by the agent during the synthesis process. 1. Ingestion points: Raw data is read by thewiki-cli.jsscript and processed by thecompile-source-page.mdandcompile-concept-page.mdprompt templates. 2. Boundary markers: The prompt templates do not include clear delimiters or instructions to ignore potential commands found within the raw source material. 3. Capability inventory: The skill has the capability to read and write local files, execute shell scripts, and update a local SQLite database. 4. Sanitization: While the skill includes path traversal protections for output files, it does not sanitize or filter the content of ingested materials for potential malicious instructions.
Audit Metadata