wiki-ingest
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources which could contain malicious instructions.
- Ingestion points: In SKILL.md, the workflow accepts user-provided text, file paths, and directory contents for ingestion.
- Boundary markers: The skill lacks explicit delimiters or instructions to the agent to treat ingested data as non-executable text, which is an absent safety best practice.
- Capability inventory: The agent is granted permission to read project files and write/update markdown files within the local wiki directory.
- Sanitization: There is no evidence of a mechanism to sanitize, escape, or filter instructions from the ingested content before it is processed by the model.
Audit Metadata