Back to skill

Security audit

知识管理工具-专业版

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly aligned with enterprise knowledge management, but its command/file authority, broad triggers, and under-described external data flows need human review before installation.

Review this skill before installing in an environment with private documents or shared team data. Use it only for the intended knowledge-base workflows, confirm the know CLI and storage locations, avoid callback_url unless the endpoint is trusted, and keep cloud embedding/API credentials in environment variables or a secret store. Review sync, permission, invite, and export commands before allowing execution.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The skill claims no extra API key is needed, but elsewhere states that cloud embedding models and external API services may be used. This inconsistency can mislead operators into enabling external integrations without properly planning credential handling, causing accidental secret exposure or unexpected data egress to third-party services.

Vague Triggers

High
Confidence
88% confidence
Finding
The trigger condition is much broader than the skill's stated knowledge-management purpose, expanding use to generic data analysis, reporting, and visualization tasks. In an agent ecosystem, this can cause the skill to be invoked in unrelated contexts where it has powerful exec/write capabilities, increasing the chance of overreach, unsafe command execution, or unintended handling of sensitive data.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill supports a callback_url for asynchronous completion but does not clearly warn that results or metadata may be sent to an external destination. This creates a data exfiltration risk because users or downstream agents may supply arbitrary URLs, causing sensitive knowledge-base content, logs, or identifiers to be transmitted off-platform without informed consent.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.