wiki-import — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited wiki-import (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
You are importing a vault's knowledge into the current vault from one of two sources produced by wiki-export:
## Related link list — no body). Lossy.wiki-export/okf/ directory) — the actual markdown files. Reconstructs full pages with their real bodies. Lossless. Use this for true vault-to-vault transfer.Either way, the import writes pages with correct frontmatter and wikilinks, then updates all vault metadata. Step 2, Step 3 (graph only), and Step 5 are shared; Step 4 forks by source type.
llm-wiki/SKILL.md (walk up CWD for .env → ~/.obsidian-wiki/config → prompt setup). This gives OBSIDIAN_VAULT_PATH.$OBSIDIAN_VAULT_PATH/AGENTS.md if it exists — apply any owner-specific conventions.Find the import source:
./wiki-export/okf/ (a directory) → ./wiki-export/graph.json (a file).Detect the source type:
.md files with OKF frontmatter (a type: key), and/or a root index.md with okf_version → OKF bundle import (skip Step 3; go to Step 4-OKF).Validate a graph.json source:
nodes (array), links (array), graph (object)If validation fails, report what's wrong and stop.
Validate an OKF bundle source:
.md file (i.e. not index.md/log.md) with parseable YAML frontmatter containing a non-empty type..md with no frontmatter or no type is skipped (with a count), not fatal — OKF consumers are permissive (OKF §9).Show a preview before importing:
graph.json:
Import preview (graph.json — stubs)
Source: <path> (exported at <graph.exported_at>)
Nodes: N total (concepts: A, entities: B, skills: C, references: D, ...)
Links: M edges (X typed, Y untyped)
Target: $OBSIDIAN_VAULT_PATHOKF bundle:
Import preview (OKF bundle — full pages)
Source: <dir> (okf_version <ver if present>)
Pages: N total (concepts: A, entities: B, skills: C, references: D, ...)
Target: $OBSIDIAN_VAULT_PATHRead the user's phrasing to determine mode. Default is merge.
| Mode | Trigger phrases | Behaviour |
|---|---|---|
merge | (default, no special phrasing) | Existing pages: update frontmatter tags/summary/relationships and add missing wikilinks; new pages: create stub. |
skip | "skip existing", "don't overwrite", "only new pages" | Leave existing pages completely untouched; only create pages that don't exist yet. |
overwrite | "overwrite", "replace existing", "force import" | Replace all matched pages with freshly reconstructed stubs regardless of existing content. |
Before writing anything, build two maps from the links array:
Adjacency map — for each node id, collect all neighbour ids (edges in either direction):
adjacency["concepts/transformers"] = ["entities/vaswani", "concepts/lstm", ...]Typed edge map — for each node id, collect outgoing typed edges only (typed: true):
typed_edges["concepts/transformers"] = [
{target: "concepts/lstm", relation: "contradicts"},
...
]Record counts: created = 0, skipped = 0, merged = 0.
For each node in nodes:
page_path = $VAULT/<node.id>.md$VAULT/concepts/)mergedcreatedskipped, continue to next nodecreatedmergedcreated---
title: <node.label>
category: <node.category>
tags: <node.tags as YAML list>
sources:
- "imported from <graph.json path>"
<if node.summary exists>
summary: "<node.summary>"
</if>
<if typed_edges[node.id] is non-empty>
relationships:
<for each {target, relation} in typed_edges[node.id]>
- target: "[[<target>]]"
type: <relation>
</for>
</if>
lifecycle: draft
lifecycle_changed: <today YYYY-MM-DD>
base_confidence: 0.5
tier: supporting
created: <ISO timestamp>
updated: <ISO timestamp>
---
# <node.label>
<node.summary paragraph if available, else omit>
## Related
<for each neighbour in adjacency[node.id], sorted alphabetically>
<if edge is typed>
- [[<neighbour>]] — <relation>
<else>
- [[<neighbour>]]
</if>
</for>If adjacency[node.id] is empty, omit the ## Related section entirely.
node.tags (deduplicated, keep existing order, append new ones).summary field and node.summary exists, add it.relationships: entries and typed_edges[node.id] — skip entries where the same (target, type) pair already exists.updated to the current ISO timestamp.## Related section. If it exists, append any missing wikilinks from adjacency[node.id] that aren't already linked anywhere in the body. If no ## Related section exists, append one with the missing links.Record counts: created = 0, skipped = 0, merged = 0, unparseable = 0.
Walk the bundle directory tree. For each .md file that is not a reserved file (index.md, log.md):
type, increment unparseable and skip the file..md stripped (e.g. concepts/transformers.md → concepts/transformers). The target page is $VAULT/<concept-id>.md.wiki-export Step 3.5):title ← title.category ← the preserved category extension key if present; else lower-case the directory prefix of the concept id (concepts/… → concepts); else derive from type (Concept→concepts, Entity→entities, Skill→skills, Reference→references, Synthesis→synthesis, Project→projects, Journal→journal).tags ← tags.summary ← description.updated ← timestamp (or now if absent).created ← the preserved created extension key if present, else now.sources ← the preserved sources extension key if present; else ["imported from OKF bundle <bundle path>"]. If a resource URL is present and not already in sources, add it.relationships, lifecycle, tier, base_confidence, …). These make the round-trip lossless..md paths become wikilinks (this restores both real cross-links and forward-references the exporter preserved per wiki-export Step 3.5):[text](../concepts/transformers.md) or [text](/concepts/transformers.md) → resolve the path (relative to this file's dir, or bundle-root for /-absolute) to a concept id → [[concepts/transformers]], or [[concepts/transformers|text]] when text differs from the target's title. The target's title comes from the bundle page when it exists; otherwise compare against the last path segment..md path relative to the current file, then strip the trailing .md from the resolved file path to recover the page id. Do not try to infer the id from directory traversal segments before resolving the full file path. This preserves round-trips for folder-note layouts like projects/social-twitter.md plus projects/social-twitter/..., where ../../social-twitter.md must restore to projects/social-twitter.[[wikilink]] (Obsidian supports these; OKF §5.3 expects them). Do not leave it as a markdown link.OBSIDIAN_LINK_FORMAT=markdown is set in config, keep markdown links (just rewrite the path to be vault-relative); do not convert to wikilinks.http(s):// links and # Citations sections untouched.tags; fill summary/sources only if missing; union relationships; refresh updated). For the body, OKF carries a real body: replace the existing body with the bundle body only if the existing page is a stub (body is just a heading + ## Related); otherwise keep the existing body and append any bundle # Citations / new ## sections not already present. Increment merged.created.skipped, continue.created.merged (label as Replaced in the summary).created.$VAULT/concepts/, etc.) exists before writing.Unlike the graph.json path, do not generate a ## Related stub section — the bundle body already contains the real cross-links.
.manifest.jsonAdd a new entry keyed by the canonical path of the graph.json file:
"<absolute path to source>": {
"ingested_at": "<ISO timestamp>",
"source_type": "wiki-export",
"pages_created": ["list/of/created/pages.md"],
"pages_updated": ["list/of/merged/pages.md"]
}Set source_type to "wiki-export" for a graph.json import or "okf-bundle" for an OKF bundle import. Key the entry by the absolute path of the source (the graph.json file or the bundle directory).
Also increment:
stats.total_sources_ingested by 1stats.total_pages by the count of pages actually created (not skipped/merged)If .manifest.json doesn't exist, create it with the standard structure:
{
"stats": {
"total_sources_ingested": 1,
"total_pages": <created count>
},
"<graph.json path>": { ... }
}index.mdFor each created or merged page:
- [[<id>]] — <summary or title> ( #tag1 #tag2) (Note: space before ( — description ( #tag) not description(#tag))
Keep categories sorted alphabetically. Create the category section if it doesn't exist.
log.mdAppend one line:
- [<ISO timestamp>] IMPORT source="<graph.json path>" pages_created=<N> pages_skipped=<K> pages_merged=<M>hot.mdRewrite the Recent Activity section to include this import as the latest entry:
- [<timestamp>] IMPORT from <graph.json path> — created X, merged Z pagesUpdate the updated: frontmatter timestamp. Leave other hot.md sections (Active Threads, Key Takeaways) intact unless they reference pages that were just created — in which case add brief mentions.
Wiki import complete → $OBSIDIAN_VAULT_PATH
Source: <source path> (<graph.json | OKF bundle>)
<graph: exported at <graph.exported_at>, N nodes, M links | okf: N pages, okf_version <ver>>
Created: <X> pages
Merged: <Z> pages (existing pages updated)
Skipped: <Y> pages (only when --skip mode was used)Only show the Skipped line if skip mode was explicitly requested. If overwrite mode was used, label merged pages as Replaced instead. For an OKF import, also report Unparseable: <U> files (no frontmatter/type, skipped) when U > 0.
merge mode is idempotent — re-running on an unchanged export will update timestamps but won't destroy content. Use overwrite only when you want to fully reset pages to stubs.links but absent from nodes (broken in the original export) will still appear as a wikilink — it just won't have a corresponding page file, which is valid.graph.json was produced with visibility filtering (noted in graph.metadata), imported pages will only reflect the filtered set. Note this in the summary if graph.graph contains a filtered key.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.