wiki-query

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes and displays content from external wiki pages, creating a potential vector for indirect prompt injection attacks.
  • Ingestion points: In scripts/query.js, the cmdSearch, cmdRelated, and cmdShow functions retrieve wiki titles, snippets, and full page content from a database and output them to the agent's console.
  • Boundary markers: While the output uses some formatting (e.g., separators like ·), there are no explicit boundary delimiters or system instructions that mandate the agent ignore any commands or behavioral overrides embedded within the wiki text.
  • Capability inventory: The script itself performs local file reading and database operations. The agent environment typically includes capabilities for file system modification, command execution, and network access.
  • Sanitization: The script performs only basic whitespace formatting on snippets and lacks any sanitization or filtering to detect or neutralize malicious instructions contained in the wiki data.
  • [DYNAMIC_EXECUTION]: The skill employs dynamic module loading to access its data storage logic.
  • In scripts/query.js, the getStore function determines the location of the database controller at runtime and uses require() on the computed distPath. This represents dynamic loading from a computed path, which is used to interface with the local project's build artifacts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:50 PM
Security Audit — agent-trust-hub — wiki-query