Back to skill

Security audit

Knowledge Bridge

Security checks for vulnerabilities and agentic risk

Overview

This skill matches a local knowledge-base pipeline, but it loads unreviewed local Python code and can bulk-write to a persistent knowledge database, so it should be reviewed before installation.

Install only if you trust the local backend module and control the referenced db directory. Before use, verify the external knowledge_bridge.py that will be imported, back up the SQLite knowledge base, and run ingest/backfill only when you intend to permanently add those records.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T07 · Tool Hijacking and Spoofing

Error
Location
knowledge_bridge.py:7
Finding

Arbitrary Module Loading Through a Precedence-Controlled External Search Path

Content
View full analysis

Vulnerability Details

File Location: knowledge_bridge.py, lines 7 and 15–20
Vulnerability Type: Untrusted Python module search-path manipulation
Risk Level: High

Vulnerable Code

python
_SRC = Path(__file__).parent.parent.parent / "db"
python
sys.path.insert(0, str(_SRC))
try:
    from knowledge_bridge import (
        ingest_latest_cycle, get_kb_stats, search_knowledge,
        backfill_all_cycles, auto_explain
    )

Technical Analysis

The skill derives a directory outside its package, inserts that directory at index zero of sys.path, and then imports an unqualified module named knowledge_bridge. Index zero has the highest normal import priority, so a file named knowledge_bridge.py in that external directory can replace the expected implementation.

In the audited deployment path, the expression resolves to /tmp/db. This directory is outside the reviewed project. If an attacker can create or replace /tmp/db/knowledge_bridge.py, Python will execute that file's top-level statements during import. The imported functions subsequently receive control over every advertised operation, including ingestion, statistics, backfill, search, and explanation.

The external implementation is not included in the project, so its database, network, and data-handling behavior cannot be verified. The project contains no direct evidence of malicious payloads, persistence, credential theft, or exfiltration; the risk arises from the unsafe loading mechanism.

Attack Path

  1. An attacker obtains write access to the derived external module directory.
  2. The attacker creates or replaces /tmp/db/knowledge_bridge.py.
  3. The attacker defines the expected exported function names and adds malicious top-level code or malicious function bodies.
  4. A user or Agent invokes any skill operation.
  5. The skill prepends /tmp/db to sys.path.
  6. Python resolves from knowledge_bridge import ... to the attacker-controlled file and immediate ...[truncated 984 chars]
Remediation
View remediation

Remediation Suggestions

  1. Package the implementation inside the skill under a unique package name and use an explicit relative import, for example:

    python
    from .bridge_backend import (
        ingest_latest_cycle,
        get_kb_stats,
        search_knowledge,
        backfill_all_cycles,
        auto_explain,
    )
    
  2. Remove runtime mutation of sys.path. In particular, do not prepend externally derived or temporary directories to the import search path.

  3. If an external implementation is operationally required:

    • Configure its location explicitly rather than deriving it through parent traversal.
    • Require an absolute, canonical path.
    • Restrict the path to an administrator-controlled, non-world-writable directory.
    • Verify file ownership and reject files writable by untrusted users.
    • Verify the module against a pinned cryptographic digest or trusted signature before loading it.
    • Load it under a unique internal module name and fail closed on any verification failure.
  4. Avoid naming the wrapper and external backend module knowledge_bridge, as the duplicate name increases import ambiguity and spoofing risk.

  5. Add deployment tests that resolve and record the exact imported module path, rejecting any module located outside the approved application directory.

  6. Align SKILL.md with the actual loading behavior. The documentation currently describes Windows paths under D:\coze-local, while the code derives an environment-dependent external db directory.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill advertises a simple knowledge-bridge function, but its documented behavior includes local database access, ingestion, search, summarization, and bulk backfill operations against specific filesystem paths. This mismatch is dangerous because users and orchestrators may invoke it without understanding that it can read from and write to persistent local data, increasing the chance of unintended data modification or overbroad access.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description is too generic and omits the concrete fact that the skill ingests data into a SQLite knowledge base and interacts with a local Python module and database. Poor disclosure is risky because operators may approve or run the skill under the false assumption that it is informational only, when it actually performs persistent local data operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The functionality section promotes automatic ingestion and backfilling into a local knowledge base without warning that these actions modify persistent local data. In a skill context, silent state-changing behavior is dangerous because it can lead to accidental data pollution, duplication, storage growth, or ingestion of sensitive historical content without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The backfill invocation is presented as a simple command even though it may trigger large-scale import of all historical cycles into persistent storage. This is risky because users may treat it as harmless, while it can cause significant data churn, long-running processing, or irreversible changes to the local knowledge base.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module title, description, docstring, argument documentation, and user-facing error/result messages are all written in Chinese, with no indication that other languages are supported or that the locale restriction is intentional and justified. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest describes only 'knowledge-bridge' without stating what the skill actually does, while the code supports several concrete operations: ingesting data into a knowledge base, backfilling historical cycles, searching stored knowledge, and auto-generating explanations. This is a semantic mismatch because the declared purpose does not communicate the breadth of behaviors implemented.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.