Wiki Ingest

Security checks across malware telemetry and agentic risk

Overview

This skill is an instruction-only wiki-ingestion helper that openly tells the agent to update markdown wiki files and does not include executable code, credentials, network access, or hidden behavior.

Install this only if you want an agent to modify an existing markdown wiki. Limit access to the intended wiki folder and review diffs for page edits, index.md, and log.md before committing or syncing changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The manifest description is broad enough to trigger on many ordinary requests involving notes, articles, reports, or summaries, which increases the chance the skill runs in contexts the user did not specifically intend. Because this skill performs persistent wiki modifications, over-broad activation can cause unintended writes, page drift, or accidental ingestion of content into the knowledge base.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The workflow explicitly updates existing pages, index.md, and log.md, but the description does not prominently warn that the skill will make persistent multi-file edits. Users may invoke it expecting analysis or summarization and instead trigger broad repository changes, which is especially risky in a git-backed or shared wiki where unintended edits propagate and are hard to review.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal