extract-wisdom
Audited by Socket on Sep 22, 2026
3 alerts found:
Anomalyx3SUSPICIOUS. The skill’s purpose broadly matches its capabilities, but it requires unsandboxed execution, processes arbitrary external content, and relies on a local wrapper script plus third-party network services with limited provenance detail in the skill itself. I found no confirmed credential harvesting, stealth, or malicious pre-execution behavior, so this is not malware, but it is a medium-risk skill due to execution trust and external content handling.
The code appears to be a document-ingestion and personal knowledge-library utility. It contains legitimate network and subprocess functionality, including optional browser-cookie use, arbitrary web fetching, remote Mermaid rendering, and npx/bunx package execution. These create meaningful privacy, SSRF, and supply-chain risks when inputs or documents are untrusted, but no clear malicious payload, credential theft beyond explicitly requested browser-cookie use, persistence, destructive behavior, reverse shell, or covert exfiltration is present. The supplied fragment also appears syntactically invalid in multiple locations and should be repaired and reviewed before execution.
The fragment appears to implement a documentation or knowledge viewer and does not show clear malware, data theft, or sabotage. It has a meaningful potential stored-XSS risk because markdown output from entry.body is inserted into innerHTML without an explicit sanitizer. URL scheme validation for source links should also be confirmed, and external CDN scripts should ideally use trusted local bundles or SRI. Assessment is limited to the shown portion and depends on the unseen marked configuration, safeHref implementation, data provenance, and diagram-rendering functions.