Back to skill

Security audit

llm-wiki-simple

Security checks for vulnerabilities and agentic risk

Overview

This skill is a scoped Markdown instruction for building a personal wiki from files the user places in a Raw directory, with expected local reads and wiki writes but no hidden execution or persistence.

Before installing, treat 00_Raw/ as an explicit input folder: only place documents there that you are comfortable having summarized by the agent/model, and review generated or overwritten pages in 01_Wiki/ if you keep manual edits there.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is designed to scan raw articles, notes, papers, text files, and PDFs and have an LLM 'understand' and rewrite them, but it does not warn users that document contents may be processed by the model or auxiliary tools. This creates a confidentiality risk because sensitive notes, unpublished papers, credentials accidentally stored in notes, or proprietary content could be exposed to model/tool processing without informed user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs the agent to create directories, write wiki pages, update an index, and overwrite same-named pages, but it does not require an explicit pre-action warning or confirmation that filesystem changes will occur. This can lead to unexpected modification of a user's project files, especially because the workflow is framed as an automated build process that may be triggered by short commands.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The style section specifies 中文为主 as a required language preference. This is a natural-language policy concern because it imposes a locale/output language without offering the user a choice or documenting that the skill is intentionally limited to a Chinese-language context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.