Agent skill

Wiki

by Encod3d-Sec in Encod3d-Sec/TORCH

Search, query, and maintain the qmd-indexed wiki - semantic search, keyword search, re-index after adding pages, check index status.

MITAuto-check passedSecurity

Install Wiki

skills CLI
$ npx skills add Encod3d-Sec/TORCH --skill wiki -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Encod3d-Sec/TORCH wiki --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/wiki .claude/skills/wiki && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
wiki
GitHub stars
329
Used in
1 other repo
Token cost
~1.1k tokens
SKILL.md length
485 words
Files
1
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Search, query, and maintain the qmd-indexed wiki - semantic search, keyword search, re-index after adding pages, check index status.

  • Works in 3 steps: Confirm the qmd binary is on PATH… → Check QMD_VAULT is set and points to the… → The index lives under ~/.qmd/ - if the…
  • Security work in your project
  • SKILL.md covers Prerequisites, Searching via MCP (preferred…, Searching via CLI and Maintenance, plus 3 more sections
  • Calls python3 and bun

What it does

Wiki is an agent skill from Encod3d-Sec/TORCH. Search, query, and maintain the qmd-indexed wiki - semantic search, keyword search, re-index after adding pages, check index status.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. It works with Model Context Protocol. The repository describes itself as: Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian. The licence is MIT.

When your agent uses it

  • Security work in your project

Example prompts

  • “/wiki”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Confirm the qmd binary is on PATH (command -v qmd); it installs to ~/.bun/bin/qmd via bun install -g @qmd/cli.
  2. Check QMD_VAULT is set and points to the current vault path (no trailing slash, no spaces encoded).
  3. The index lives under ~/.qmd/ - if the collection is missing, run qmd update to rebuild from scratch.

What it can do on your machine

Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3
    • bun

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Wiki loads about 1.1k tokens when it runs. Until then it costs about 34 tokens; SKILL.md has 485 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~34
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 485 words, ~1,129 tokens.

Download SKILL.mdSave it as .claude/skills/wiki/SKILL.md (or your agent's skills folder).
name
wiki
description
Search, query, and maintain the qmd-indexed wiki - semantic search, keyword search, re-index after adding pages, check index status.
type
cli

Wiki Search and Maintenance

qmd is a CLI + MCP server that provides semantic and keyword search over wiki/. The MCP server (wiki-search) exposes two tools consumed by Claude Code directly. The CLI is used for maintenance (re-index, status).

All paths are relative to the vault root ($QMD_VAULT).


Prerequisites

QMD_VAULT must point to your vault root (no trailing slash). Export it in your shell profile:

bash
export QMD_VAULT="/path/to/your/ObsidianVaults/ClaudeBrain"

If a new session does not inherit it, prefix commands with QMD_VAULT=... qmd ... or source your profile. qmd is installed as a bun global (bun install -g @qmd/cli); if the qmd command is not found, ensure ~/.bun/bin is on PATH.


Searching via MCP (preferred in-session path)

When the wiki-search MCP is active, prefer these tools over the CLI - they avoid the 3-4 second model load on every invocation:

ToolPurpose
mcp__wiki-search__qmd_querySemantic (vector) search - use for concepts, techniques, intent
mcp__wiki-search__qmd_searchKeyword (substring) search - use for exact strings, tool names, CVE IDs

CLAUDE.md rule: never read wiki/index.md to find pages - always search first.


Searching via CLI

Use when MCP is unavailable or for one-off maintenance.

Semantic query (5 results, default):

bash
qmd query "CDN bypass origin IP"

Semantic query (custom result count):

bash
qmd query -n 10 "JWT empty secret"

Keyword search:

bash
qmd keyword "pnpm"

Output format: [score] path/relative/to/wiki/ followed by a chunk of the matching content.


Maintenance

Re-index after adding or editing pages (run once after a bulk write, not per file):

bash
qmd update

Expected output: Indexing wiki... Done. N chunks indexed.

The CUDA warning about an old driver is harmless - the model runs on CPU.

Check index size:

bash
qmd status

Output: Collection: wiki Chunks: N

Integrity and catalog upkeep

These run automatically at SessionStart (via engagement-init.py); run them by hand after a bulk edit, rename, or before sharing:

bash
python3 scripts/gen_index.py     # rebuild wiki/index.md catalog (idempotent; --check tests only)
python3 scripts/lint-wiki.py     # broken links, dead script refs, frontmatter gaps, stale index, lean areas
python3 scripts/build_moc.py     # rebuild graph hubs so every page stays reachable

lint-wiki.py exits non-zero on hard problems - use it as a pre-share / pre-commit gate. index.md and the *-moc.md hubs are generated; never hand-edit them.


Show full SKILL.md (191 more words)Show less

Promote candidates

Generic, reusable knowledge found live during an engagement is staged to a review queue under targets/<eng>/wiki-candidates/ (gitignored) the moment it is confirmed, not at engagement end. It reaches wiki/ only through the leak-gated promoter.

bash
python3 scripts/wiki-promote.py --list             # pending candidates (slug, kind, page)
python3 scripts/wiki-promote.py --review <slug>    # read one candidate in full
python3 scripts/wiki-promote.py --promote <slug>   # or: --promote all

--promote runs scripts/check-leaks.sh --file on the candidate BODY. If a client marker is present it refuses and writes nothing; if clean it merges into wiki/<target_page> (dedup by slug), sets status: promoted, archives the file to wiki-candidates/_promoted/, and re-indexes (gen_index.py + qmd update). Stage a new candidate with scripts/wiki-stage.py --kind <default-cred|api-pattern|technique> --slug <slug>. This is the only path that writes engagement-derived knowledge into wiki/, so the client-data boundary is enforced by code, not prose.


Broken install recovery

If qmd fails:

  1. Confirm the qmd binary is on PATH (command -v qmd); it installs to ~/.bun/bin/qmd via bun install -g @qmd/cli.
  2. Check QMD_VAULT is set and points to the current vault path (no trailing slash, no spaces encoded).
  3. The index lives under ~/.qmd/ - if the collection is missing, run qmd update to rebuild from scratch.

Files

PathPurpose
~/.bun/bin/qmdqmd CLI + MCP binary (bun global)
~/.qmd/local search index
$QMD_VAULT/wiki/the markdown corpus that gets indexed

© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/wiki of Encod3d-Sec/TORCH.

Open the folder on GitHubat commit d21b6c9

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Encod3d-Sec/TORCH, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Wiki next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Wiki compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Wiki this skillEncod3d-Sec/TORCH3291 repos~1.1kAutomated safety check: PassMIT
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Forensifyalexgreensh/repo-forensics188—~2.5kAutomated safety check: NotesCustom licence
Hol Guardhashgraph-online/hol-guard815—~542Automated safety check: PassApache-2.0
Setuphashgraph-online/hol-guard815—~443Automated safety check: PassApache-2.0
Security Reviewktnyt/cclsp675—~565Automated safety check: PassMIT

Similar skills

  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    188 GitHub stars~2.5k tokensUpdated 11 days ago
    SecurityAuto-check: notes
  • Hol Guard

    hashgraph-online/hol-guard

    Run HOL Guard scanner and guard operations via uv run hol-guard.

    815 GitHub stars~542 tokensUpdated today
    SecurityAuto-check passed
  • Setup

    hashgraph-online/hol-guard

    Install or initialize HOL Guard local runtime protection for Claude Code.

    815 GitHub stars~443 tokensUpdated today
    SecurityAuto-check passed
  • Security Review

    ktnyt/cclsp

    Request a security expert assessment for code changes that touch child process spawning, file system access, configuration loading, or environment variable handling.

    675 GitHub stars~565 tokensUpdated 7 mo ago
    SecurityAuto-check passed
  • Status

    hashgraph-online/hol-guard

    Check HOL Guard local protection status for Claude Code without changing configuration.

    815 GitHub stars~231 tokensUpdated today
    SecurityAuto-check passed

More from Encod3d-Sec/TORCH

All 35 skills in this repo
  • Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

    329 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • CTF Campaign Driver

    Encod3d-Sec/TORCH

    Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.

    329 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Adaptive Web Fuzzing

    Encod3d-Sec/TORCH

    Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

    329 GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Hunt Idor

    Encod3d-Sec/TORCH

    IDOR / BOLA hunting - two-account methodology, identifier discovery and UUID leak chaining, the trusted-identifier test, GraphQL node and nested-object IDOR, cross-tenant escalation, write and…

    329 GitHub starsUsed in 1 repo~2.6k tokens
    Auto-check passed
  • Screenshot Burp

    Encod3d-Sec/TORCH

    Capture a Burp Suite Repeater request/response as a PoC image (targets/<eng/poc/) by driving the Burp MCP + the Kali GUI.

    329 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check: notes
  • Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.

    329 GitHub stars~611 tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Wiki

What does Wiki do?

Search, query, and maintain the qmd-indexed wiki - semantic search, keyword search, re-index after adding pages, check index status. Wiki is an agent skill from Encod3d-Sec/TORCH. Search, query, and maintain the qmd-indexed wiki - semantic search, keyword search, re-index after adding pages, check index status.

When should I use Wiki?

Wiki fits situations like: security work in your project.

How do I install Wiki in Claude Code?

Run `npx skills add Encod3d-Sec/TORCH --skill wiki -a claude-code`. Or copy the skill folder (skills/wiki in Encod3d-Sec/TORCH) into .claude/skills/wiki in your project. Claude Code loads it when a task matches its description.

How do I install Wiki in Codex?

Run `npx skills add Encod3d-Sec/TORCH --skill wiki -a codex`. Or copy the skill folder (skills/wiki in Encod3d-Sec/TORCH) into .agents/skills/wiki in your project. Codex loads it when a task matches its description.

Can I use Wiki in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill wiki -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wiki, .gemini/skills/wiki, .github/skills/wiki and .opencode/skills/wiki in your project.

What does Wiki need to run?

Going by SKILL.md and its folder, Wiki needs the command-line tools its instructions call (python3 and bun). Our summary lists: Python 3.

Does Wiki access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Wiki safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Wiki use?

Wiki is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Wiki use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Wiki?

Skills that share tags, products or a category with Wiki: Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Forensify (alexgreensh/repo-forensics, 188 stars), Hol Guard (hashgraph-online/hol-guard, 815 stars) and Setup (hashgraph-online/hol-guard, 815 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Wiki?

Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.

Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.