Back to skill

Security audit

LLM Wiki

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local wiki-maintenance workflow that persistently reads and writes user-designated wiki files, with some optional tooling risks users should understand.

Install this if you want an agent to maintain a persistent local markdown wiki and you are comfortable with it creating and modifying files under the chosen wiki root. Review proposed changes before broad ingest, audit, or cleanup runs; avoid storing secrets in the wiki; pin and isolate optional npm/pip tooling; and treat generated HTML/JavaScript outputs as active untrusted content until reviewed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/tooling-tips.md:83
Finding

Unpinned Third-Party Package Installation Creates a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation
``` 3. Use a hash-pinned requirements file and install with hash enforcement: ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 4. Record and review all transitive dependencies through a reproducible lock file. 5. Install the tool in a dedicated virtual environment with no unnecessary credentials or sensitive environment variables: ```bash python3 -m venv .venv-qmd . .venv-qmd/bin/activate python3 -m pip install --require-hashes -r requirements.txt ``` 6. Prefer signed releases or artifacts obtained through the publisher's verified canonical installation channel. 7. Review package source and installation metadata before updating the pinned version. 8. If package identity and provenance cannot be established, remove the installation instruction or replace it with a locally audited alternative. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill clearly directs the agent to read and write local files across a wiki tree, but it declares no explicit tool scope or permission boundaries. Without an allowed-tools/permissions declaration, an orchestrator may grant broader file access than intended, increasing the chance of unintended reads/writes outside the wiki root.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The frontmatter description narrows the skill's intent to a research-oriented LLM wiki and explicitly says it is not for general note-taking, daily journals, or non-wiki Obsidian use. Later, the documentation lists 'Personal wiki — journal entries, notes, ideas compiled into a personal encyclopedia' as a use case, which directly contradicts that stated limitation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill repeatedly instructs the agent to persist raw sources, generated summaries, query outputs, logs, and audit resolutions to disk, but it never requires explicit user confirmation before creating or modifying files. In a system where agents can act autonomously, this can lead to silent data persistence, overwriting content, or storing sensitive material from user queries or imported sources without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document explicitly encourages having the LLM generate interactive HTML with JavaScript and save it to local outputs, but provides no warning about script execution, data exfiltration, or unsafe embedding inside Obsidian/browser contexts. In this skill, generated artifacts may be opened locally or embedded in plugins/viewers, which increases the chance that active content from untrusted prompts or source material could execute with the user's browser privileges.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.