logseq web article

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says, but it also tells the agent to automatically install an unpinned companion skill without a clear approval step.

Install only if you are comfortable with article URLs being fetched, converted, passed to logseq-article-archive, and saved into Logseq. Before use, ask the agent to get your approval before installing any missing companion skill, and avoid private or login-only pages unless you intend to archive their contents.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly states it will automatically install another skill if `logseq-article-archive` is missing, but this behavior is not surfaced as a clear user warning or consent step. Automatic dependency installation expands the trust boundary and can introduce unreviewed code or unexpected capabilities, especially because the fetched article content is then forwarded into the newly installed skill.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal