tiangong-wiki-skill

Warn

Audited by Socket on May 4, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose and local file operations are coherent for wiki management, and there is no evidence of credential theft or explicit exfiltration. However, the required CLI is underspecified and its provenance cannot be verified from the skill text, creating a medium supply-chain trust concern rather than clear malicious behavior.

Confidence: 84%Severity: 52%
AnomalyLOW
src/utils/process.ts

No direct indicators of malware (e.g., exfiltration, credential theft, reverse shells, or obfuscated payloads) are present in the provided fragment. However, the code exposes high-impact primitives: detached background process spawning (child.unref()) with caller-influenced arguments/env, and OS handler invocation using attacker-influenced target, plus optional logfile path-based stdio redirection that can write/append to arbitrary filesystem paths. This should be treated as security-sensitive and require strict upstream validation/allowlisting of target/logFile/extraArgs and careful threat-modeling of where these inputs originate.

Confidence: 62%Severity: 56%
Audit Metadata
Analyzed At
May 4, 2026, 09:55 AM
Package URL
pkg:socket/skills-sh/Biaoo%2Ftiangong-wiki%2Ftiangong-wiki-skill%2F@2e10cd97f3a98128de086e849acd2050d1bd26d7