wiki-ingest

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources which could contain malicious instructions.
  • Ingestion points: In SKILL.md, the workflow accepts user-provided text, file paths, and directory contents for ingestion.
  • Boundary markers: The skill lacks explicit delimiters or instructions to the agent to treat ingested data as non-executable text, which is an absent safety best practice.
  • Capability inventory: The agent is granted permission to read project files and write/update markdown files within the local wiki directory.
  • Sanitization: There is no evidence of a mechanism to sanitize, escape, or filter instructions from the ingested content before it is processed by the model.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:09 PM
Security Audit — agent-trust-hub — wiki-ingest