Back to skill

Security audit

LLM Knowledge Bases

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent local wiki-maintenance helper, but it should be reviewed because it combines persistent write workflows with broad prefixless triggers and an unpinned npx runtime install path.

Install only if you are comfortable letting the configured MCP runtime read and update a local knowledge-base vault. Prefer a pinned npm runtime version instead of @latest, run it with least privilege against only the intended vault, and use the explicit $llm-knowledge-bases prefix plus read-only or dry-run wording when you do not want changes.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:133
Finding

Unpinned npm Package Is Downloaded and Executed via npx

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 133–147
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

bash
claude mcp add llm-knowledge-bases -- \
  npx -y --package @harrylabs/llm-knowledge-bases@latest \
  llm-knowledge-bases-mcp \
  --vault-root /absolute/path/to/your/obsidian-vault

For other MCP-capable agents:

bash
npx -y --package @harrylabs/llm-knowledge-bases@latest \
  llm-knowledge-bases-configs --vault-root /absolute/path/to/your/obsidian-vault

Technical Analysis

The documented installation commands use npx -y to download and execute @harrylabs/llm-knowledge-bases@latest. The latest npm tag is mutable and does not identify a fixed, previously reviewed artifact. The -y option also suppresses the normal installation confirmation.

Consequently, the effective executable code can change after this Skill has been reviewed. This repository does not include the npm runtime implementation, pin an exact runtime version, provide a lockfile, or specify an integrity digest that would allow users to verify the downloaded package.

The package name is consistent with the declared product and there is no evidence in the audited repository that the current package is malicious. The vulnerability is the unsafe dependency acquisition and execution model, which makes future compromise of the npm package, publisher account, or release process directly actionable.

Attack Path

  1. An attacker compromises the npm publisher account, package release process, or another component capable of changing the version referenced by the latest tag.
  2. The attacker publishes a malicious package version and assigns or causes the latest tag to reference it.
  3. A user follows either installation command from README.md.
  4. npx -y downloads the attacker-controlled version without an interactive confirmation.
  5. The package binary executes with ...[truncated 906 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace @latest with an exact, reviewed package version, for example:
    bash
    npx -y --package @harrylabs/llm-knowledge-bases@0.4.1 \
      llm-knowledge-bases-mcp \
      --vault-root /absolute/path/to/your/obsidian-vault
    
  2. Verify that the pinned version is the runtime version intended for Skill release 1.2.2; update it only through an explicit review and release process.
  3. Use a lockfile or package-manager integrity metadata where the installation workflow supports it.
  4. Publish and verify a cryptographic integrity digest or signed provenance for the expected package artifact.
  5. Avoid automatic -y execution in security-sensitive setup documentation, or clearly warn users that the command downloads and executes third-party code.
  6. Document the expected npm registry, package publisher, exact version, and verification procedure.
  7. Run the MCP server with least privilege and restrict its filesystem access to the intended Vault where the host supports sandboxing.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (19)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README states the skill can be triggered without an explicit namespace prefix and gives ordinary-language commands as valid invocations. That weakens activation boundaries and increases the chance that normal conversation is interpreted as authorization to run file-reading and file-writing wiki operations, causing unintended actions in the user's repository.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

These shortcut prompts are broad conversational phrases that could plausibly appear in normal discussion, yet they map to repository-modifying actions such as note cleanup, page promotion, and ongoing maintenance. In an agent environment, ambiguous trigger phrases can cause accidental activation and unauthorized changes to local content.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The README explicitly encourages omitting the skill prefix when context seems clear, then lists generic phrases that should be treated as commands. This makes the activation surface highly ambiguous and materially raises the risk of prompt injection, accidental tool routing, or unintended file modifications when users are merely discussing their wiki.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Stating that users can often omit the explicit skill prefix, without defining strict alternative trigger rules, materially weakens invocation boundaries. In practice this can cause the skill to fire on ordinary conversation, quoted examples, or unrelated instructions, which is especially dangerous for a workflow that can mutate local Markdown knowledge bases and continue prior tasks autonomously.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The install command uses @latest via an unpinned npx --package invocation, so users may execute whatever version is published at invocation time rather than a reviewed build. That creates a supply-chain risk where a compromised publisher account, malicious release, or breaking update can change behavior unexpectedly and execute code locally during setup.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This is a second unpinned npx --package example that fetches and executes the latest published package at runtime. In a security-sensitive agent/tooling context, that increases exposure to package compromise or silent behavior changes without user review.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This is a natural-language policy issue because it imposes a language default rather than offering a neutral language choice or explicit opt-in. The file includes Chinese prompt examples, so forcing outward-facing artifacts to English by default may override user expectations or organizational locale requirements.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The release notes explicitly promote invoking the skill through short natural-language requests rather than a tightly scoped command format. That increases the chance the agent will activate the workflow from ambiguous user text or surrounding context, causing unintended knowledge-base inspection or modification actions. In a skill that can continue workflows, clean up content, repair source IDs, or add derived pages, broad routing language meaningfully expands accidental activation risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The phrase '继续推进我的这份库' is highly open-ended and does not specify scope, target files, allowed actions, or safety constraints. An agent matching this phrase could resume prior workflows or perform broad changes across a wiki without the user explicitly authorizing what to inspect, ingest, clean, or modify in the current turn.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly states that the prefix is recommended but not required when a request "clearly matches" the skill, which broadens activation beyond a uniquely scoped invocation. In an agent environment, this creates prompt/skill confusion risk: ordinary user phrasing can unintentionally route into a tool-using workflow that performs knowledge-base reads and writes, increasing the chance of unauthorized or surprising state changes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The listed entry points include broad phrases like "check my wiki," "clean up these pages," and "what pages are missing?" that can plausibly appear in normal conversation without the user's intent to invoke a powerful maintenance skill. Because this skill can trigger searches, reads, repairs, note creation, and index rebuilds, ambiguous activation materially raises the risk of unintended tool execution and persistence into the managed vault.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Chinese intent lexicon maps very common conversational phrases such as "看一下", "检查一下", and "整理一下" to concrete workflows, including maintenance and compilation behavior. This makes accidental activation more likely for Chinese-language users, especially because some mapped intents are write-capable and the routing logic treats these phrases as strong hints rather than requiring a clearly namespaced invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly performs persistent knowledge-base operations such as ingesting source material, updating wiki notes, rebuilding indexes, and archiving outputs, but the description does not warn the user that invoking it can modify long-lived vault state. This can lead to unintended data persistence, silent content changes, and surprise archival of user queries or source-derived outputs, which is a security and privacy concern even if the tool behavior is otherwise legitimate.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly states that the '$llm-knowledge-bases' prefix is optional and that short natural-language requests should still trigger the guide when intent is merely 'clear'. This creates prompt-routing ambiguity: ordinary user phrases can accidentally invoke vault-management behavior, including write-capable workflows, without a strong namespace or confirmation boundary.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger list contains broad everyday phrases such as 'check my wiki', 'clean up these pages', and similar Chinese equivalents, mapping them directly to operational tool flows. Because these phrases are common and underspecified, an attacker or accidental conversational context could cause unintended tool use, including maintenance or content-writing actions, especially where the guide says not to write 'unless asked' but still treats vague phrasing as sufficient routing.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The default prompt advertises multiple very broad natural-language trigger phrases such as '继续推进我的这份库' and notes that explicit skill routing is optional, which increases the chance the skill is invoked when the user intended a general assistant action instead. In an agent system, ambiguous auto-routing can cause unintended processing or modification of a knowledge base, especially because some example phrases imply state-changing actions rather than read-only behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

Line L05 describes adding 'compact Chinese one-line prompts for common wiki workflows.' For a markdown file, this is a natural-language locale policy concern because it suggests language-specific behavior without indicating user choice, opt-in, or a documented region-specific requirement.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The shortcuts normalize short requests like '检查一下我的 wiki' and '整理一下 AI 相关内容' as sufficient instructions. While examples are useful, these particular phrasings are broad enough to overlap with routine assistance requests unless stronger invocation constraints are enforced elsewhere.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The file provides dedicated Chinese routing hints and one-line Chinese examples, which introduces a language-specific behavior surface. There is no accompanying statement that language routing is optional, user-selected, or limited to a justified locale-specific deployment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.