Back to skill

Security audit

Knowhere

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed helper skill for a document-ingestion plugin, with cleanup commands that users should treat carefully.

Before installing, make sure you trust the external Knowhere plugin and publisher. Only ingest documents or URLs you are comfortable storing in the Knowhere scope, and preview or list documents before using remove or clear operations because they may delete stored document state.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill explicitly instructs use of `knowhere_remove_document` and `knowhere_clear_scope` for cleanup, but it does not warn that these operations are destructive or recommend confirmation before execution. In an agent setting, this increases the chance of accidental deletion of stored documents or clearing the current scope when a user did not clearly intend irreversible cleanup.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.