wiki

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a persistent knowledge base that ingests, stores, and retrieves markdown content, creating a surface for instructions to be embedded in data.
  • Ingestion points: Content enters the system through the wiki_ingest and wiki_add tools defined in SKILL.md.
  • Boundary markers: The instructions do not specify any delimiters or boundary markers to distinguish between data and instructions within the wiki pages.
  • Capability inventory: The skill has capabilities for reading, writing, and deleting files within the project's .omc/wiki/ directory.
  • Sanitization: There is no mention of sanitizing or validating ingested content before it is stored or when it is retrieved for use by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:34 PM
Security Audit — agent-trust-hub — wiki