wiki-viewer
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection and shell expansion vulnerability surface through its 'Copy as command' feature.
- Ingestion points:
scripts/render.jsreads untrusted query data from thewiki_seedstable in the local SQLite database (~/.pro-workflow/data.db), which holds data collected during research loops. - Boundary markers: Completely absent. No safeguards or warnings are provided to prevent the execution of embedded command payloads.
- Capability inventory:
scripts/render.jspossesses file-system write capabilities viafs.writeFileSyncto generate the HTML file artifact. - Sanitization: The script relies solely on
JSON.stringify()to escape the query content. While this prevents basic quote breaking, it does not sanitize shell expansions or command substitutions (e.g.,$(command)or`command`), which will be evaluated if the copied string is pasted into a Unix shell environment.
Audit Metadata