wiki-craft

Security checks across malware telemetry and agentic risk

Overview

This skill transparently helps an agent create and maintain a local markdown wiki, with no evidence of hidden code, exfiltration, or destructive behavior.

Install this if you want an agent to maintain a local markdown wiki for you. Before using it, choose the wiki root directory carefully and review proposed writes during ingest, especially when using generic phrases like "ingest this" that may otherwise be interpreted as a request to update the wiki.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrase "ingest this" is highly generic and can match many ordinary user requests that are unrelated to a personal wiki. In a skill with Read, Write, Edit, and Bash permissions, ambiguous activation increases the chance the agent enters this workflow unexpectedly and performs filesystem reads or wiki writes outside the user's intended scope.

Vague Triggers

Low
Confidence
75% confidence
Finding
The description uses broad intents like "build a knowledge base" and "what does the wiki say" without clear exclusion criteria, which can cause over-selection of the skill for loosely related requests. Although the content is not overtly malicious, this weak scoping is risky because the skill is designed to create and update persistent files, so accidental invocation can lead to unintended modifications or confusing behavior.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal