skills/sammcj/agentic-coding/llm-wiki/Gen Agent Trust Hub

llm-wiki

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data—including URLs, documents, and text pastes—to create and update wiki articles.
  • Ingestion points: External content is retrieved via the ingest command, as detailed in references/ingest.md.
  • Boundary markers: The skill employs specific frontmatter fields (fidelity: distilled) and formatted Sources/Raw sections to delineate synthesized text from source material.
  • Capability inventory: The agent can write to the filesystem, execute local scripts, and perform network requests to fetch content.
  • Sanitization: Guidelines in references/ingest.md and references/scoping.md mandate filtering out secrets, API keys, and PII before saving content to the wiki.
  • [COMMAND_EXECUTION]: The skill uses uv run to execute bundled Python scripts (scripts/lint_wiki.py and scripts/lint_mermaid.py) to automate structural health checks and mermaid syntax validation. It also utilizes shell commands such as grep to find backlinks and identify knowledge gaps within the markdown files as described in references/lint.md and references/gaps.md.
  • [EXTERNAL_DOWNLOADS]: The skill retrieves content from external URLs or documents provided by the user during the ingestion process to populate the knowledge base.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 07:36 AM
Security Audit — agent-trust-hub — llm-wiki