Back to skill

Security audit

Wiki

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches a personal wiki purpose, but its default setup installs a persistent local server and its build/git behavior can retain or publish private wiki content too broadly.

Review this before installing if your wiki may contain private notes, credentials, raw sources, or business information. Use it only if you are comfortable with a ~/wiki repository, automatic local commits, an autostarting loopback web server, and possible remote publication when bootstrap --remote or build --push is used; avoid heartbeat memory scanning unless you explicitly want those notes considered for wiki gaps.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T06 · System Persistence

Error
Location
scripts/bootstrap.sh:111
Finding

Automatic Installation of a Persistent Background Web Server

Content
View full analysis
"${PLIST}" << EOF Label dev.wiki.server ProgramArguments ${PYTHON_PATH} -m http.server ${SERVE_PORT} --bind 127.0.0.1 --directory ${WIKI_DIR}/site RunAtLoad KeepAlive StandardOutPath /tmp/wiki-server.log StandardErrorPath /tmp/wiki-server.log EOF launchctl load "${PLIST}" echo "✅ Static server running on port ${SERVE_PORT}" fi elif command -v systemctl &>/dev/null; then SERVICE="${HOME}/.config/systemd/user/wiki-server.service" if [[ ! -f "${SERVICE}" ]]; then mkdir -p "$(dirname "${SERVICE}")" cat > "${SERVICE}" << EOF [Unit] Description=Wiki Static Server After=network.target [Service] ExecStart=$(which python3) -m http.server ${SERVE_PORT} --bind 127.0.0.1 --directory ${WIKI_DIR}/site Restart=always [Install] WantedBy=default.target EOF systemctl --user daemon-reload systemctl --user enable --now wiki-server echo "✅ Static server running on port ${SERVE_PORT}" fi fi ``` ### Technical Analysis The boots ...[truncated 1908 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/bootstrap.sh:76
Finding

Unpinned Python Dependencies and Unsafe System-Package Fallback

Content
View full analysis
/dev/null; then echo "Installing MkDocs..." if command -v pipx &>/dev/null; then pipx install mkdocs pipx inject mkdocs mkdocs-material elif command -v pip3 &>/dev/null; then pip3 install --user mkdocs mkdocs-material 2>/dev/null || \ pip3 install --break-system-packages mkdocs mkdocs-material else echo "❌ No pip3 or pipx found. Install MkDocs manually." exit 1 fi fi ``` ### Technical Analysis The script installs `mkdocs` and `mkdocs-material` without version constraints or integrity hashes. Consequently, the effective dependency code can change after the Skill itself has been audited. Installation may execute package build hooks or other package-controlled installation logic. The final fallback uses `--break-system-packages`, which bypasses protections for an externally managed Python environment. This can alter or conflict with packages managed by the operating system. The dependency names match the documented project requirements, and no typo-squatted names, custom indexes, or known malicious packages were identified in the reviewed code. The risk arises from mutable resolution and unsafe environment modification rather than evidence that the named packages are currently malicious. ### Attack Path 1. The bootstrap script runs on a host where `mkdocs` is unavailable. 2. `pipx` or `pip3` resolves the latest available package versions from the configured package index. 3. A compromised upstream release, compromised index, or maliciously configured index supplies attacker-controlled package content. 4. Installation or subsequent invocation executes that package content under the user's account. 5. If the user-level installation fails, the script retries with `--br ...[truncated 458 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/build.sh:18
Finding

Broad Git Staging Can Commit and Publish Unintended Sensitive Files

Content
View full analysis
/dev/null; then git push echo "✅ Pushed to remote" fi else echo "No changes to commit" fi ``` ### Technical Analysis `git add -A` stages every unignored change in the entire `~/wiki` repository. It is not restricted to generated articles or known configuration files. The documented workflow encourages users to place raw source material under `docs/raw/`; such material can contain private or sensitive information. Although remote publication requires the explicit `--push` argument, files captured by an earlier broad commit can be pushed later. The script checks only that an `origin` URL exists; it does not show the destination, verify repository visibility, inspect staged content, or request confirmation. The documentation is also inconsistent: the implementation pushes only with `--push`, while the final “Build & Deploy” section in `SKILL.md` states that the build pushes to a remote. This inconsistency can cause users or Agents to misunderstand the disclosure boundary. ### Attack Path 1. A user places a sensitive source, credential-bearing file, private note, or unrelated artifact anywhere under `~/wiki`. 2. The file is not covered by `.gitignore`. 3. A normal `scripts/build.sh` invocation executes `git add -A`. 4. The sensitive file is included in the generated commit without a per-file revie ...[truncated 735 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Note
Location
references/heartbeat-integration.md:1
Finding

Optional Heartbeat Integration Expands Access into Agent Memory

Content
View full analysis
24h: scan `~/wiki/docs/` articles for: - Contradictions — facts/numbers/claims that conflict across articles - Stale data — outdated references, old dates with "current"/"latest" language - Missing links — references to topics without articles - Gaps — topics discussed in recent memory/ daily notes but not in wiki - Dead cross-links — broken See also links - Orphan pages — pages with no inbound links - Weak pages — articles too thin to be useful on their own 3. Fix within ~/wiki/docs/: broken links, typos, missing cross-links, orphan pages 4. Flag to user: contradictions (with quotes), stale data, suggested new articles, weak pages 5. Append a lint entry to `docs/log.md` 6. If changes made: run `scripts/build.sh` 7. Update timestamp ``` Add `"lastWikiLint": null` to your `heartbeat-state.json`. ## Notes - The **gap detection** step (checking `memory/` daily notes) is the only part that reads files outside `~/wiki/`. Remove that line if you want the lint fully scoped to the wiki directory. - All fixes are written only to `~/wiki/docs/`. - `build.sh` commits locally by default. Add `--push` if you want automatic remote pushes. ``` ### Technical Analysis The optional heartbeat workflow instructs the Agent to read `memory/` daily notes outside the declared wiki directory. This expands the data-a ...[truncated 1418 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description frames the capability as wiki maintenance, but the instructions also authorize persistent system changes, automatic git commits, optional remote pushes, and operation on a fixed home-directory path. This mismatch is dangerous because a user or calling system may invoke the skill expecting local content organization, while it can also publish or persist data beyond that scope and alter the host environment.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to persistently file conversation-derived knowledge and update multiple related pages without any rule to exclude secrets, personal data, credentials, or sensitive business information. This creates a durable retention channel where transient chat content can be replicated across the wiki and become harder to discover, review, or delete.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instruction to proactively offer filing synthesized answers encourages preservation of conversation content that users may not expect to become long-term records. In a personal wiki context, synthesized answers can still contain sensitive facts, decisions, or internal analysis, and once stored they may later be committed or pushed elsewhere.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

An append-only activity log that records sources, touched pages, and summaries for every ingest, lint, and filed answer creates a secondary metadata trail about the user's information and behavior. Even if article contents are later edited or removed, the log can preserve sensitive provenance and semantic summaries indefinitely, increasing exposure and complicating deletion.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file contains contradictory instructions: earlier text says pushing is optional with --push, while the Build & Deploy section says every content change pushes to remote. In an autonomous agent context, this ambiguity can lead to unintended exfiltration of wiki contents if the agent follows the more aggressive instruction path.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill does not prominently warn that build/deploy behavior may transmit wiki content to a configured remote repository. Because the wiki is designed to ingest conversation-derived knowledge and raw sources, omission of a clear publication warning increases the risk of accidental disclosure of sensitive or private information.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Automatically running scripts/build.sh introduces script-execution risk, and the note about adding --push enables network-affecting behavior that exceeds passive wiki linting. If the build script is modified, unsafe, or attacker-influenced, the heartbeat could repeatedly execute unintended commands and potentially publish changes remotely without sufficient user review.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The bootstrap script goes beyond creating a local wiki and performs system modification by installing packages and creating persistent background services. That expands the trust boundary of the skill: running it changes the host environment and leaves long-lived processes behind, which is risky for an agent skill whose stated purpose is wiki management rather than host administration.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The optional remote configuration and immediate git push enable publication of local wiki contents to an external destination during bootstrap. In a personal knowledge-base skill, this creates a data exfiltration path that may expose sensitive notes if a remote URL is supplied by an agent, prompt injection, or mistaken automation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

This finding is a duplicate signal on the same LaunchAgent setup block. While the matched token alone is not harmful, it is part of a genuine persistence workflow that results in automatic restart and background execution for the wiki server.

Content

Scanner excerpt · scripts/bootstrap.sh (reported line 116)May include surrounding context.

sh
# Create LaunchAgent (macOS) or systemd service (Linux) for static serving
if [[ "$(uname)" == "Darwin" ]]; then
  PLIST="${HOME}/Library/LaunchAgents/dev.wiki.server.plist"
  if [[ ! -f "${PLIST}" ]]; then
    PYTHON_PATH=$(which python3)
    cat > "${PLIST}" << EOF

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

This finding is a duplicate signal on the same LaunchAgent setup block. While the matched token alone is not harmful, it is part of a genuine persistence workflow that results in automatic restart and background execution for the wiki server.

Content

Scanner excerpt · scripts/bootstrap.sh (reported line 116)May include surrounding context.

sh
# Create LaunchAgent (macOS) or systemd service (Linux) for static serving
if [[ "$(uname)" == "Darwin" ]]; then
  PLIST="${HOME}/Library/LaunchAgents/dev.wiki.server.plist"
  if [[ ! -f "${PLIST}" ]]; then
    PYTHON_PATH=$(which python3)
    cat > "${PLIST}" << EOF

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

This line begins the conditional flow that creates a LaunchAgent file if absent, contributing to user-session persistence on macOS. In a wiki bootstrap script, creating OS-level autostart entries is broader than necessary and increases host-side risk even if intended only for convenience.

Content

Scanner excerpt · scripts/bootstrap.sh (reported line 117)May include surrounding context.

sh
# Create LaunchAgent (macOS) or systemd service (Linux) for static serving
if [[ "$(uname)" == "Darwin" ]]; then
  PLIST="${HOME}/Library/LaunchAgents/dev.wiki.server.plist"
  if [[ ! -f "${PLIST}" ]]; then
    PYTHON_PATH=$(which python3)
    cat > "${PLIST}" << EOF
<?xml version="1.0" encoding="UTF-8"?>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

This is another duplicate token match inside the plist creation block. The XML declaration is not dangerous by itself, but it is part of constructing a persistent LaunchAgent that will auto-run the local server at login.

Content

Scanner excerpt · scripts/bootstrap.sh (reported line 119)May include surrounding context.

sh
PLIST="${HOME}/Library/LaunchAgents/dev.wiki.server.plist"
  if [[ ! -f "${PLIST}" ]]; then
    PYTHON_PATH=$(which python3)
    cat > "${PLIST}" << EOF
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

This duplicate alert again reflects the same LaunchAgent persistence block. The skill context makes this more concerning because a content-management helper should not silently establish background services on the user's machine.

Content

Scanner excerpt · scripts/bootstrap.sh (reported line 121)May include surrounding context.

sh
PYTHON_PATH=$(which python3)
    cat > "${PLIST}" << EOF
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>Label</key>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

This duplicate alert again reflects the same LaunchAgent persistence block. The skill context makes this more concerning because a content-management helper should not silently establish background services on the user's machine.

Content

Scanner excerpt · scripts/bootstrap.sh (reported line 121)May include surrounding context.

sh
PYTHON_PATH=$(which python3)
    cat > "${PLIST}" << EOF
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>Label</key>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

The plist body defines the service label for a macOS LaunchAgent, which is part of installing persistence. Persistence is risky because it leaves a long-lived process configuration that survives beyond the initial command and may be overlooked by users.

Content

Scanner excerpt · scripts/bootstrap.sh (reported line 122)May include surrounding context.

sh
cat > "${PLIST}" << EOF
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>Label</key>
    <string>dev.wiki.server</string>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

This line closes the generated plist immediately before it is loaded, so it is part of the same persistence setup. The issue is the completed creation of a user autostart artifact for the HTTP server, not the XML syntax itself.

Content

Scanner excerpt · scripts/bootstrap.sh (reported line 146)May include surrounding context.

sh
<key>StandardErrorPath</key>
    <string>/tmp/wiki-server.log</string>
</dict>
</plist>
EOF
    launchctl load "${PLIST}"
    echo "✅ Static server running on port ${SERVE_PORT}"

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

This duplicate finding points to the same activation of the LaunchAgent persistence path. The matched variable reference is not independently dangerous, but it is inseparable from the real issue of loading an autostart agent.

Content

Scanner excerpt · scripts/bootstrap.sh (reported line 148)May include surrounding context.

sh
</dict>
</plist>
EOF
    launchctl load "${PLIST}"
    echo "✅ Static server running on port ${SERVE_PORT}"
  fi
elif command -v systemctl &>/dev/null; then

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

This duplicate finding points to the same activation of the LaunchAgent persistence path. The matched variable reference is not independently dangerous, but it is inseparable from the real issue of loading an autostart agent.

Content

Scanner excerpt · scripts/bootstrap.sh (reported line 148)May include surrounding context.

sh
</dict>
</plist>
EOF
    launchctl load "${PLIST}"
    echo "✅ Static server running on port ${SERVE_PORT}"
  fi
elif command -v systemctl &>/dev/null; then

Session Persistence

Medium
Category
Rogue Agent
Confidence
96% confidence
Finding

Enabling a user systemd service with --now establishes persistence across sessions and causes the HTTP server to start automatically. Persistence is a sensitive capability because it creates a long-lived execution foothold and may continue serving content after the user believes the bootstrap process has ended.

Content

Scanner excerpt · scripts/bootstrap.sh (reported line 168)May include surrounding context.

sh
WantedBy=default.target
EOF
    systemctl --user daemon-reload
    systemctl --user enable --now wiki-server
    echo "✅ Static server running on port ${SERVE_PORT}"
  fi
fi

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script can push local wiki changes to a remote repository when invoked with --push, which exceeds a purely local build/compile operation and introduces an external side effect. In an agent context, this creates a data exfiltration and unintended publication risk because compiled or raw wiki content may be sent to a remote origin without an explicit, narrowly scoped confirmation step.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The instruction 'You maintain a personal wiki for the user' establishes mandatory behavior, but the file does not impose any specific language or locale requirement. Because SQP-3 only covers natural-language policy violations such as forced language or locale constraints, no stronger policy issue is present here.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documented heartbeat integration expands the skill's data access beyond the declared wiki scope by reading heartbeat-state.json and especially memory/ daily notes. Even though presented as optional, this creates scope creep and a privacy boundary violation risk because a wiki-maintenance skill can inspect unrelated user data and derive content from it.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script comments suggest temporary static serving, but the implementation installs a LaunchAgent or systemd user service that restarts automatically. This mismatch is dangerous because it conceals persistence behavior from reviewers and users, increasing the chance they will approve host changes without understanding the long-term effect.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.