Back to skill

Security audit

Llmwiki

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed LLM-backed personal wiki skill with expected network and file access, but its privacy wording should be read carefully.

Install only if you trust the PyPI/GitHub package and the LLM endpoint you configure. Use a dedicated API key with limits where possible, ingest only content you are comfortable storing locally and sending to that provider, and keep the optional web/API/MCP server and autonomous worker restricted to trusted environments.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The documentation makes absolute privacy claims ('all data stays local' and 'nothing is sent anywhere except the configured LLM API') while elsewhere describing outbound network access for URL fetching, corpus plugins, and scheduled worker activity. This can mislead users into trusting the skill with sensitive material under a false assumption about data flow, increasing the chance of unintended disclosure or unsafe deployment decisions.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.