Kimi Cli Headless Execution

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only skill for running Kimi CLI in automation, with the main risks disclosed and tied to that purpose.

Before installing, understand that this skill may guide an agent to run Kimi CLI using your authenticated Kimi account and may enable automatic file edits or shell commands with --yolo. Use narrow work directories, require explicit confirmation before automatic approval, avoid sensitive system paths, and use session or Wire modes only when you intend to reuse context or expose a local service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal