Back to skill

Security audit

Qiaomai Skills

Security checks across malware telemetry and agentic risk

Overview

The skill's code, metadata, and SKILL.md are internally consistent with a memory/knowledge-graph/reporting toolkit and do not request unexplained credentials or perform obvious exfiltration.

This skill appears coherent with its description, but before installing: (1) Review or sandbox its filesystem writes (the registry metadata declares ~/.qiaomai/ as storage); (2) Only provide optional API keys (OpenAI/Perplexity/Grok) if you trust the integration and prefer using scoped keys; (3) If you need stronger guarantees, inspect the full source for any network I/O or os.environ usage (not observed in the provided fragments) or run the skill in an isolated environment first; (4) Periodically inspect and clean ~/.qiaomai/ if you store sensitive data there.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.