Back to skill

Security audit

LLM Wiki Karpathy

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent local wiki helper, but users should review it because documented setup can execute an unpinned remote npm runtime with access to the chosen vault.

Install only if you trust the runtime publisher and understand that the selected vault can be read and modified. Prefer a pinned reviewed runtime version instead of @latest, avoid npx -y where confirmation is practical, use a dedicated vault path, and invoke write-capable tasks with the explicit $llm-wiki-karpathy prefix plus clear limits or dry-run wording.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:133
Finding

Unpinned npm Runtime Is Downloaded and Executed Automatically

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 133–146
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

The documented setup commands execute the mutable @latest version of an external npm package:

bash
claude mcp add llm-wiki-karpathy -- \
  npx -y --package @harrylabs/llm-wiki-karpathy@latest \
  llm-wiki-karpathy-mcp \
  --vault-root /absolute/path/to/your/obsidian-vault
bash
npx -y --package @harrylabs/llm-wiki-karpathy@latest \
  llm-wiki-karpathy-configs --vault-root /absolute/path/to/your/obsidian-vault

Technical Analysis

The @latest tag is mutable and does not identify a specific, reviewed package version. Each invocation can therefore download and execute different code without any corresponding change to this Skill. The npx -y option suppresses the package installation confirmation, further reducing the opportunity for users to inspect unexpected dependency changes.

The external npm runtime is not included in the audited project, so its implementation and future releases are outside this audit's verification boundary. If the package publisher account, npm package, release process, or an upstream dependency is compromised, malicious code could be distributed through the existing documented command.

Attack Path

  1. An attacker compromises the npm publisher account, release pipeline, package contents, or a relevant upstream dependency.
  2. The attacker publishes a malicious version under @harrylabs/llm-wiki-karpathy and causes the mutable latest tag to resolve to it.
  3. A user follows either installation command in README.md.
  4. npx -y downloads the current package without requesting installation confirmation.
  5. The package executable runs with the invoking user's operating-system privileges.
  6. The malicious process can access resources available to that user, including the vault path explic ...[truncated 574 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace @latest with an exact reviewed version, consistent with the documented runtime release:

    bash
    npx --package @harrylabs/llm-wiki-karpathy@0.4.4 \
      llm-wiki-karpathy-mcp \
      --vault-root /absolute/path/to/your/obsidian-vault
    
  2. Update the configuration-helper command in the same way.

  3. Avoid -y where interactive confirmation is practical, so unexpected installation behavior remains visible.

  4. Prefer a lockfile-backed installation workflow for repeatable dependency resolution.

  5. Verify and publish the expected npm package integrity digest and provenance information.

  6. Review new runtime versions before updating the pinned version, and use automated dependency and provenance checks in the release pipeline.

  7. Run the MCP runtime with least privilege and restrict its filesystem access to the intended vault where the host environment supports sandboxing.

Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (14)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README explicitly says the skill prefix is optional and suggests natural-language requests can trigger the workflow. That broadens activation conditions enough that ordinary user text like 'check my wiki' or 'continue improving my library' could unintentionally invoke a skill that reads and writes repository content.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The shortcut prompt '继续推进我的这份库' is extremely broad and context-dependent, making it unsafe as an activation trigger. In a normal conversation, similar language could easily appear without the user intending to authorize automated maintenance and write-back actions.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

These examples present short, everyday prompts without the explicit skill prefix as valid commands, which increases the chance of accidental triggering in unrelated conversations. Because the skill supports maintenance, repairs, promotions, and index rebuilds, mistaken activation can lead to unintended modifications of the wiki.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README describes writing important answers back into the wiki automatically, but does not foreground that this changes user data. When paired with ambiguous invocation patterns, this raises the risk of unexpected file creation or modification in the local vault.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The install command fetches and executes the latest package version at runtime via npx, which creates a supply-chain risk and undermines reproducibility. If the upstream package is compromised or a breaking release is published, users may execute unreviewed code on their machine simply by following the README.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This command also relies on npx to resolve and run the package without an exact pinned version, exposing users to remote code execution through a dependency or publisher compromise. Because the package is intended to integrate with local files and a vault root path, the blast radius includes the user's local knowledge base and agent environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This is a natural-language locale policy issue applicable to all file types. The statement imposes English as the default output language unless the user explicitly requests otherwise, rather than first offering or preserving user language choice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

These activation phrases are broad enough to match ordinary requests like checking or looking over a knowledge base, which can cause the skill to route unexpectedly without an explicit invocation. Because the skill includes write-capable maintenance and ingestion workflows, accidental activation can lead to unintended wiki modifications or tool execution beyond the user's actual intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The listed trigger phrases include vague requests such as cleanup, adding pages, or answering from the wiki that are hard to distinguish from normal conversation. In a skill that can create, repair, and rebuild knowledge-base content, this ambiguity increases the chance of unintended state-changing operations and weakens user-consent boundaries.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The Chinese routing lexicon contains very generic conversational phrases like 'take a look' or 'organize this a bit' that are common in everyday use and can unintentionally activate the skill. Since the skill can transition from inspection into maintenance or content creation, these broad hints create elevated risk of accidental tool use and unauthorized wiki changes for Chinese-language users.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly states that the $llm-wiki-karpathy prefix is optional and that short natural-language requests should still trigger the guide when intent is merely 'clear.' This creates ambiguous activation conditions where common user phrases can unintentionally invoke this skill's workflow, increasing the chance of unintended tool use or writes in the managed vault.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The listed triggers include broad phrases such as 'check my wiki,' 'clean up these pages,' and similar Chinese equivalents that overlap with normal conversation. Because several of these phrases map directly to operational flows that may inspect, modify, or rebuild content, an attacker or even a normal user could activate the skill unintentionally or steer it into performing actions beyond what was clearly requested.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The default prompt advertises highly generic natural-language triggers such as '整理一下 AI 相关内容' and '继续推进我的这份库', which can overlap with ordinary user conversation and cause unintentional routing to this skill. That ambiguity can lead the agent to invoke the skill on broader requests than intended, increasing the chance of unintended file modifications or processing of sensitive repository content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

Line L09 states the skill added "compact Chinese one-line prompts for common wiki workflows." This is a natural-language locale constraint presented without any indication that users can choose language or that the Chinese-only behavior is justified for a region-specific use case.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.