Back to skill

Security audit

wilma

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Wilma school-system helper that uses stored local credentials to read student data, with no evidence of hidden, destructive, or unrelated behavior.

Install this only if you intend the agent to access Wilma student information using your local Wilma session. Treat grades, attendance notes, messages, and downloaded attachments as sensitive, and keep downloads limited to items needed for the current task.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The skill explicitly instructs the agent to use a locally stored Wilma config containing session credentials and to download linked news resources, including authenticated resources. Because this accesses student-related data and can fetch external content, the lack of an upfront privacy/scope warning and explicit user-consent guidance creates a real risk of unintended access to sensitive educational records or downloading third-party content without the user understanding the implications.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.