wiki-enrich

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external academic summary services and uses it to modify local markdown files, creating a vulnerability to indirect prompt injection.
  • Ingestion points: Fetches paper overviews and abstracts from alphaxiv.org and export.arxiv.org via WebFetch and curl (Step 2.3).
  • Boundary markers: The instructions do not specify any boundary markers or instructions for the agent to ignore or delimit potentially malicious commands embedded within the fetched external text.
  • Capability inventory: The skill utilizes Edit, Write, and Bash tools to modify the local filesystem based on the processed data.
  • Sanitization: There is no evidence of sanitization or validation of the fetched external content before it is processed by the agent.
  • [EXTERNAL_DOWNLOADS]: The skill performs network operations to fetch data from remote sources.
  • Evidence: Retrieves content from alphaxiv.org and export.arxiv.org to provide source material for the wiki enrichment.
  • Note: These domains are well-known academic resources and the fetches are consistent with the skill's primary purpose.
  • [COMMAND_EXECUTION]: The skill executes local scripts and shell commands to manage the wiki and log actions.
  • Evidence: Uses Bash to resolve script paths and execute a local helper script (research_wiki.py) via python3 for logging and query pack management.
  • Evidence: Uses curl to interact with the arXiv API.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 02:42 PM
Security Audit — agent-trust-hub — wiki-enrich