语雀知识库导出

Security checks across malware telemetry and agentic risk

Overview

This skill does what it advertises: it exports a user-selected Yuque knowledge base to local Markdown, but the exported content and browser session should be treated as sensitive.

Install only if you want to export Yuque repositories you are allowed to copy. Use a dedicated browser profile or account for sensitive workspaces, verify the target Yuque URL, and choose a specific output folder because the skill can save many Markdown files and optional images locally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to create directories and write a potentially large number of Markdown files to a user-specified path, but the user-facing description and usage section do not clearly warn about that side effect. This can lead to unexpected filesystem changes, clutter, overwriting risks, or writing into sensitive locations if the output path is broad or mistyped.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The skill relies on the user's authenticated browser session and directs the agent to call internal Yuque APIs to enumerate and export repository contents, but it does not present a clear privacy warning to the user before doing so. This is dangerous because users may not realize the skill can access all content visible to their logged-in session, including private knowledge-base material, and then persist that data locally.

VirusTotal

57/57 vendors flagged this skill as clean.

View on VirusTotal