wiki-enrich
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external academic summary services and uses it to modify local markdown files, creating a vulnerability to indirect prompt injection.
- Ingestion points: Fetches paper overviews and abstracts from
alphaxiv.organdexport.arxiv.orgviaWebFetchandcurl(Step 2.3). - Boundary markers: The instructions do not specify any boundary markers or instructions for the agent to ignore or delimit potentially malicious commands embedded within the fetched external text.
- Capability inventory: The skill utilizes
Edit,Write, andBashtools to modify the local filesystem based on the processed data. - Sanitization: There is no evidence of sanitization or validation of the fetched external content before it is processed by the agent.
- [EXTERNAL_DOWNLOADS]: The skill performs network operations to fetch data from remote sources.
- Evidence: Retrieves content from
alphaxiv.organdexport.arxiv.orgto provide source material for the wiki enrichment. - Note: These domains are well-known academic resources and the fetches are consistent with the skill's primary purpose.
- [COMMAND_EXECUTION]: The skill executes local scripts and shell commands to manage the wiki and log actions.
- Evidence: Uses
Bashto resolve script paths and execute a local helper script (research_wiki.py) viapython3for logging and query pack management. - Evidence: Uses
curlto interact with the arXiv API.
Audit Metadata