Back to skill

Security audit

Li Summarize

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent summarization helper, but it uses third-party model APIs, installs an unpinned global npm package, and can persist API keys without restrictive file permissions.

Review this skill carefully before installing. Avoid using it on confidential local files or private videos unless you trust the configured provider or use a local endpoint such as Ollama. Do not run the installer as root, prefer a pinned/local install of the summarize CLI, and ensure ~/.summarize is chmod 700 and ~/.summarize/config.json is chmod 600 if you store an API key there.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
scripts/install.sh:10
Finding

Unpinned npm Package Is Installed Globally

Content
View full analysis
/dev/null; then echo "Installing summarize CLI..." npm install -g @steipete/summarize fi ``` ### Technical Analysis The installation script installs `@steipete/summarize` without specifying an exact version, lockfile, or integrity hash. Consequently, npm resolves the package version available under the registry's current distribution tag when installation occurs. npm packages can execute lifecycle scripts during installation. Therefore, the effective code executed by this command is not fully represented by the audited project and may change after the audit. The `-g` option also installs the package globally, increasing its visibility and potentially the scope of filesystem modifications. Although no evidence shows that the named package is currently malicious, this pattern exposes users to package-account compromise, malicious future releases, registry compromise, and unexpected upstream changes. ### Attack Path 1. An attacker compromises the npm package, its publisher account, or the package distribution process. 2. The attacker publishes a malicious release and assigns it to the tag resolved by an unversioned npm installation. 3. A user runs `scripts/install.sh` on a system where `summarize` is not already available. 4. `npm install -g @steipete/summarize` downloads the attacker-controlled release. 5. npm executes any package lifecycle scripts and installs the resulting command globally. 6. The malicious package executes with the permissions of the account running the installer. ### Impact Assessment Successful exploitation permits arbitrary code execution with the installer's privileges. Depending on those privileges, the malicious package could access user files and environment credentials, mod ...[truncated 217 chars]
Remediation
View remediation
``` - Verify the package's expected integrity and provenance before installation. - Use a lockfile and an installation workflow that enforces integrity metadata where feasible. - Prefer a project-local installation over `-g` to reduce the modification scope. - Disable npm lifecycle scripts if the package does not require them: ```bash npm install --ignore-scripts @steipete/summarize@ ``` - Do not run the installation as root or through `sudo`. - Establish a controlled dependency-update process in which new versions are reviewed and tested before changing the pinned version. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup.sh:33
Finding

API Key Is Persisted Without Enforced Restrictive File Permissions

Content
View full analysis
"$CONFIG_FILE" << EOF { "model": "$MODEL", "openaiBaseUrl": "$BASE_URL", "openaiApiKey": "$API_KEY", "length": "medium", "language": "zh-CN", "timeout": "2m" } EOF ``` ### Technical Analysis The script reads `OPENAI_API_KEY` into `API_KEY` and writes it directly into `~/.summarize/config.json` as plaintext. It does not set a restrictive `umask`, explicitly create the directory with mode `0700`, or enforce file mode `0600`. For a newly created file, shell redirection generally requests mode `0666`, which is then restricted only by the process's current umask. With a common umask of `022`, the resulting file can be mode `0644`, making the API key readable by other local users. The directory may similarly be created with broadly traversable permissions. If the file already exists, its previous permissions remain in effect. Persisting the credential also increases its exposure period beyond the setup process and makes it available to local processes capable of reading the user's files. ### Attack Path 1. A user exports a valid `OPENAI_API_KEY`. 2. The user runs `scripts/setup.sh` under a permissive umask or with an existing broadly readable configuration file. 3. The script writes the key to `~/.summarize/config.json` without applying restrictive permissions. 4. Another local account, process, backup collector, or unintended file reader accesses the configuration file. 5. The exposed key is used to submit requests to the configured API provider, consume the account's quota, or access provider capabilities granted to that credential. ### Impact Assessment Exploitation does not directly grant operating-system privilege escalation, but it can disclose the user's API ...[truncated 337 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (32)

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

export OPENAI_BASE_URL="https://api.deepseek.com/v1" export OPENAI_API_KEY="your-api-key"

summarize "url" --model deepseek-chat summarize "url" --model deepseek-coder

text

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 225)May include surrounding context.

export OPENAI_BASE_URL="https://api.deepseek.com/v1" export OPENAI_API_KEY="your-api-key"

summarize "url" --model deepseek-chat summarize "url" --model deepseek-coder

text

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

export OPENAI_API_KEY="your-api-key"

summarize "url" --model deepseek-chat summarize "url" --model deepseek-coder

text

### 7. 智谱 AI (Zhipu)

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

export OPENAI_BASE_URL="https://open.bigmodel.cn/api/paas/v4" export OPENAI_API_KEY="your-api-key"

summarize "url" --model glm-4-plus summarize "url" --model glm-4-flash summarize "url" --model glm-4

text

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

export OPENAI_API_KEY="your-api-key"

summarize "url" --model glm-4-plus summarize "url" --model glm-4-flash summarize "url" --model glm-4

text

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 99)May include surrounding context.

summarize "url" --model glm-4-plus summarize "url" --model glm-4-flash summarize "url" --model glm-4

text

### 8. MiniMax (稀宇)

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

export OPENAI_BASE_URL="https://api.minimax.chat/v1" export OPENAI_API_KEY="your-api-key"

summarize "url" --model MiniMax-Text-01 summarize "url" --model abab6.5s-chat

text

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

export OPENAI_BASE_URL="http://localhost:11434/v1" export OPENAI_API_KEY="not-needed"

summarize "url" --model llama3 summarize "url" --model qwen2.5:72b

text

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 138)May include surrounding context.

export OPENAI_BASE_URL="http://your-oneapi-server:3000/v1" export OPENAI_API_KEY="your-key"

summarize "url" --model gpt-4 summarize "url" --model claude-3

text

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 139)May include surrounding context.

export OPENAI_API_KEY="your-key"

summarize "url" --model gpt-4 summarize "url" --model claude-3

text

## 预设配置(推荐)

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
93% confidence
Finding

This example explicitly encourages summarizing YouTube content with an external provider but does not warn that transcripts, extracted audio-derived text, metadata, or related content may be sent to a third party. Users may assume the tool only accesses the URL locally, leading to unintended disclosure of watched content or associated private material.

Content

Scanner excerpt · SKILL.md (reported line 163)May include surrounding context.

md
summarize "https://news.ycombinator.com" --model qwen/qwen2.5-72b-instruct

# 总结 YouTube 视频
summarize "https://youtube.com/watch?v=xxx" --model deepseek-chat

# 总结本地 PDF
summarize "/path/to/file.pdf" --model glm-4-plus

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
97% confidence
Finding

This example shows summarizing a local PDF with an external model (glm-4-plus) without any caution that the file's contents may leave the user's machine. That creates a substantial data-leak risk because users may feed confidential documents, contracts, research, or internal files into a remote API unintentionally.

Content

Scanner excerpt · SKILL.md (reported line 166)May include surrounding context.

md
summarize "https://youtube.com/watch?v=xxx" --model deepseek-chat

# 总结本地 PDF
summarize "/path/to/file.pdf" --model glm-4-plus

# 指定输出长度
summarize "https://example.com" --length medium

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly supports summarizing URLs, local files, and YouTube content through third-party OpenAI-compatible APIs, but the description does not warn users that submitted content may be transmitted off-host to external providers. This can cause unintentional disclosure of sensitive local documents or private content to remote model vendors.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The sample recommended preset configuration hard-codes "language": "zh-CN", which imposes a locale choice in the skill's natural-language instructions. The documentation does not frame this as optional or offer users a choice of output language, so it can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 254)May include surrounding context.

bash
# 如果缺少 ffmpeg (YouTube 音频处理)
sudo apt install ffmpeg  # Ubuntu/Debian
sudo yum install ffmpeg  # CentOS
brew install ffmpeg      # macOS

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 255)May include surrounding context.

bash
# 如果缺少 ffmpeg (YouTube 音频处理)
sudo apt install ffmpeg  # Ubuntu/Debian
sudo yum install ffmpeg  # CentOS
brew install ffmpeg      # macOS

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/install.sh (reported line 15)May include surrounding context.

sh
fi

# 创建配置文件目录
mkdir -p ~/.summarize

# 配置文件路径
CONFIG_FILE="$HOME/.summarize/config.json"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generated default configuration sets "language": "zh-CN", which forces a specific locale for the skill by default. This is a natural-language policy issue because the script does not present a language choice or obtain user opt-in before applying the locale.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
},
  "moonshot": {
    "name": "Moonshot AI (月之暗面)",
    "baseUrl": "https://api.moonshot.cn/v1",
    "models": ["moonshot/kimi-k2-0711-preview", "moonshot/kimi-long"]
  },
  "deepseek": {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 189)May include surrounding context.

md
},
  "moonshot": {
    "name": "Moonshot AI (月之暗面)",
    "baseUrl": "https://api.moonshot.cn/v1",
    "models": ["moonshot/kimi-k2-0711-preview", "moonshot/kimi-long"]
  },
  "deepseek": {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/install.sh (reported line 70)May include surrounding context.

sh
},
  "moonshot": {
    "name": "Moonshot AI (月之暗面)",
    "baseUrl": "https://api.moonshot.cn/v1",
    "models": ["moonshot/kimi-k2-0711-preview", "moonshot/kimi-long"]
  },
  "deepseek": {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

md
},
  "deepseek": {
    "name": "DeepSeek",
    "baseUrl": "https://api.deepseek.com/v1",
    "models": ["deepseek-chat", "deepseek-coder"]
  },
  "zhipu": {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 190)May include surrounding context.

md
},
  "deepseek": {
    "name": "DeepSeek",
    "baseUrl": "https://api.deepseek.com/v1",
    "models": ["deepseek-chat", "deepseek-coder"]
  },
  "zhipu": {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 222)May include surrounding context.

md
},
  "deepseek": {
    "name": "DeepSeek",
    "baseUrl": "https://api.deepseek.com/v1",
    "models": ["deepseek-chat", "deepseek-coder"]
  },
  "zhipu": {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/install.sh (reported line 75)May include surrounding context.

sh
},
  "deepseek": {
    "name": "DeepSeek",
    "baseUrl": "https://api.deepseek.com/v1",
    "models": ["deepseek-chat", "deepseek-coder"]
  },
  "zhipu": {

Static analysis

No suspicious patterns detected.