deepwiki
Pass
Audited by Gen Agent Trust Hub on Feb 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- COMMAND_EXECUTION (LOW): The skill provides shell command examples for 'gh api' and 'claude mcp add' to fetch data and configure the environment.
- EXTERNAL_DOWNLOADS (LOW): The instructions guide users to register an external MCP server from mcp.deepwiki.com, which is an untrusted third-party source.
- DATA_EXFILTRATION (LOW): The use of the GitHub CLI (gh) utilizes the user's existing authentication, posing a minor risk of data exposure if the agent is directed to sensitive repository data.
- PROMPT_INJECTION (LOW): The skill processes external documentation content, creating a surface for indirect prompt injection. [Ingestion points: deepwiki.com, GitHub READMEs; Boundary markers: Absent; Capability inventory: gh api, mcp_tools; Sanitization: Absent].
Audit Metadata