Back to skill

Security audit

Llm Wiki Admin

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate wiki-management skill, though it can modify an Obsidian wiki and has broad activation wording.

Install this only if you want an agent to manage a specific Obsidian-based wiki. Before using it, be explicit about the vault/project path, confirm planned file writes for ingestion, and state your preferred output language if source-language mirroring is not desired.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Natural-Language Policy Violations

Medium
Confidence
85% confidence
Finding
The skill explicitly states '语言跟随资料', which can override the user's preferred output language based solely on source material. This is risky because it may ignore user intent or system-level language expectations, causing unsafe disclosure, review failures, or missed warnings when users cannot effectively understand the generated content.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger description is overly broad and uses common phrases such as adding an article to a wiki or asking whether the wiki contains something, while also saying the skill must be used whenever related terms are mentioned. This can cause frequent unintended activation, pulling the agent into file-writing and knowledge-base administration flows even when the user only made a casual reference, increasing the risk of incorrect tool use and unintended modifications.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The mode-selection examples include generic words like '问题', '查一下', and '读这篇文章', which are common across many unrelated tasks. In this context, those loose triggers are dangerous because the skill has authority to read/write knowledge-base files and invoke dependent skills, so an ambiguous request may route into wiki operations without sufficient confirmation.

Static analysis

No suspicious patterns detected.