LLM Knowledge Bases

Security checks across malware telemetry and agentic risk

Overview

The skill's files and instructions are coherent with a local-first Markdown wiki workflow and do not request unrelated credentials or suspicious installs.

This skill appears coherent and local-first: it expects a runtime that provides kb_* tools to read/compile/search/write the vault, and the SKILL.md explicitly forbids direct file tinkering. Before installing or running anything: (1) ensure the kb_* runtime tools you expect are present — if they are missing, the skill correctly says to stop rather than guessing; (2) only run the scaffold script (init_llm_kb_repo.sh) in a safe location and review the files it will create; (3) if you plan to follow README install instructions that call npx or clawhub publish, verify and trust the external package (@harrylabs) and the network actions they perform; (4) the skill requests no credentials, but be careful when granting any agent autonomous execution in environments with sensitive files — autonomous invocation is normal but increases blast radius. Overall the package is internally consistent with its described purpose.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal