Back to skill

Security audit

Anki

Security checks across malware telemetry and agentic risk

Overview

This Anki skill is a disclosed, purpose-aligned guidance package with limited local preference storage and strong warnings around risky Anki operations.

Before installing, understand that the skill can use a small local Anki preference/memory folder to remember study settings and past context. It does not instruct the agent to directly change your Anki database, but you should still review any guidance involving imports, deletes, note-type changes, or upload/download sync prompts carefully and make a .colpkg backup first.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill gives one-way sync advice that can lead to irreversible overwriting of the other side, and the nearby wording is operational rather than strongly cautionary. In this context, destructive sync actions are legitimate Anki tasks, but presenting them without explicit confirmation and backup-first guidance increases the risk of accidental data loss.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs the agent to read local preference and memory files from the user's home directory automatically on first use, without any explicit user-facing disclosure or consent step. Even though the files are app-specific, they may contain personal study history, habits, exam dates, deck names, or other sensitive context, and automatic access increases privacy risk if the user did not expect local file reads.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.