Back to skill

Security audit

Llm Wiki

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed local Markdown wiki workflow that reads user-provided source files and writes generated wiki pages, with no embedded code or hidden execution behavior.

Install only if you want an agent to manage a local Markdown wiki. Confirm the wiki root before init or ingest, review planned file writes for important repositories, keep sensitive raw/ content offline unless you explicitly allow search, and use memory only for harmless preferences.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger conditions are broad and ambiguous, covering common terms like 'wiki', '知识库', and '整理资料'. In an agentic environment, this can cause the skill to activate during ordinary conversation and begin file reads, indexing, or write-oriented planning outside the user's precise intent, increasing the chance of unintended workspace modification or data processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes creating directories, generating pages, updating indexes, appending logs, and optionally initializing Git, but does not prominently warn that it will modify the user's workspace. Without explicit disclosure and consent, a user may invoke what sounds like an organizational assistant and unintentionally allow broad write operations across project files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

该技能描述、触发条件和操作规范均以中文固定表达,未说明是否仅面向中文用户,也未提供语言切换或用户选择机制。按照语言/locale 政策,若技能实际上限定特定语言,应明确告知其适用范围或允许用户选择。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
73% confidence
Finding

The architecture defines raw/ as immutable source material, yet the same document includes personal notes and ideas under raw/ and describes ingest around materials being added there. While not a direct code contradiction, this is an intent-level inconsistency in the operational guidance: immutable archival input and actively maintained notes are different models.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The documentation permits internet_search for supplemental context without disclosing that this may send queries or derived user/project information to an external service. In a knowledge-management workflow, source titles, topics, or snippets may contain sensitive or proprietary information, so silent network use creates a confidentiality risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill is described throughout as a local Markdown wiki workflow built around reading raw/ files, writing wiki/ pages, and generating local lint outputs. Adding network search and cross-session memory expands the capability beyond the stated core purpose, and the body of the document does not define when those capabilities are necessary to perform init, ingest, query, or lint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.