LLM Knowledge Bases
Security checks across malware telemetry and agentic risk
Overview
The skill's files and instructions are coherent with a local-first Markdown wiki workflow and do not request unrelated credentials or suspicious installs.
This skill appears coherent and local-first: it expects a runtime that provides kb_* tools to read/compile/search/write the vault, and the SKILL.md explicitly forbids direct file tinkering. Before installing or running anything: (1) ensure the kb_* runtime tools you expect are present — if they are missing, the skill correctly says to stop rather than guessing; (2) only run the scaffold script (init_llm_kb_repo.sh) in a safe location and review the files it will create; (3) if you plan to follow README install instructions that call npx or clawhub publish, verify and trust the external package (@harrylabs) and the network actions they perform; (4) the skill requests no credentials, but be careful when granting any agent autonomous execution in environments with sensitive files — autonomous invocation is normal but increases blast radius. Overall the package is internally consistent with its described purpose.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
No VirusTotal findings
