Back to skill

Security audit

Wiki Capture (Dexio)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed wiki-capture helper that reads session material and records selected non-secret decisions or facts, with no executable install code or hidden behavior found.

Before installing, decide which wiki and transcript locations this skill may use, review any scheduled use, and expect it to write only small, sourced, non-secret items after filtering or asking when uncertain.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill says to use it when a person says "remember this", "note that", or "put that in the wiki," and also "on a schedule over past agent sessions." Phrases like "remember this" and "note that" overlap with common conversational language, and the schedule-based trigger lacks clear scope constraints, making activation boundaries ambiguous.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
objecting is not a decision. Where a credential is kept is worth filing; the value never
   is.
3. **Check each survivor against the wiki** (`wiki-orient`, search step). Already recorded:
   skip it. If the session showed the page is wrong or out of date, do not just overwrite
   it: follow `wiki-conflicts` (superseded when something changed, corrected when the page
   was wrong), which keeps a dated line of the old claim.
4. **File each item with `wiki-record`**: on the page that owns it, smallest edit, dated,

Static analysis

No suspicious patterns detected.